Join our Newsletter — 33% off our NHI Course

Shadow Volume Copy

Shadow Volume Copies are point-in-time snapshots used in Windows environments to support recovery of files and systems. Ransomware actors often delete them to remove easy rollback options, which makes restoration slower and increases pressure to pay. Protecting backup integrity requires isolating copies from the production environment.

What Shadow Volume Copy Means in Practice

Shadow Volume Copy is a Windows recovery mechanism, not a backup strategy on its own. It creates point-in-time snapshots that help restore files or systems quickly after deletion, corruption, or failed changes.

The key idea is that it preserves a previous state of data without stopping the live system. That makes it useful for fast rollback, but it also means the copy usually reflects the same trust boundary as the host that created it.

How Shadow Volume Copies Support Recovery

In normal operations, shadow copies give administrators a fast restore path for recently changed or deleted data. They are especially valuable when the recovery goal is local, surgical, and time-sensitive, such as recovering a single file or a small set of system changes.

Because they are snapshots, they capture only what existed at the point in time they were taken. They do not replace retention-based backup design, off-host replication, or tested disaster recovery processes. Recovery value is highest when shadow copies are treated as one layer in a broader resilience plan.

Windows shadow copy behavior is documented in Microsoft’s Volume Shadow Copy Service documentation, which explains how the snapshot service supports backup and restore workflows.

Why Shadow Volume Copies Matter to Attackers and Defenders

Ransomware crews often target shadow copies because removing them reduces an organization’s easy rollback options. If the quickest local recovery point is gone, defenders may face longer outage windows, more manual restoration work, and greater pressure to accept attacker demands.

This makes shadow copies a resilience control with a clear security consequence: the stronger the attacker’s ability to erase local recovery points, the weaker the organization’s ability to restore without paying or rebuilding from slower sources.

That relationship is also why protecting recovery data matters as much as protecting the production host itself. Microsoft’s guidance on backup and restore using VSS is useful context for understanding the recovery path attackers try to disrupt.

Backup Integrity and Isolation Requirements

Shadow copies are most effective when they are isolated from the same administrative control plane as the systems they protect. If an attacker can reach the host, the storage, or the management path with enough privilege, the snapshot may be deleted, altered, or rendered useless at the same time as the primary data.

That is why shadow copies should be understood as a convenience for rapid restoration, not as a substitute for offline, immutable, or separately governed backups. The practical security question is whether recovery data can survive compromise of the production environment.

For a broader control model around resilience, the NIST Cybersecurity Framework 2.0 is a useful reference for organizing recovery and resilience expectations.

Windows hardening guidance such as CIS Benchmarks also helps reduce the chance that backup-related settings, services, or permissions become easy targets.

Risk and Threat Considerations

Shadow Volume Copies are a high-value recovery target because they can be removed quickly once an attacker gains sufficient privilege on a Windows system. When they disappear, the organization loses an easy local recovery path and may need to fall back to slower, less convenient restore options.

Failure mechanism: An attacker with administrative or equivalent access deletes snapshot data, disables the service path that creates it, or damages the storage relationship that makes the copies usable for restore.

Impact: Recovery time increases, operational disruption grows, and ransomware pressure becomes more effective because the defender’s quickest rollback option has been removed.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0, NIST SP 800-53 Rev 5 and CIS Controls v8 set the governance and control requirements practitioners need to meet.

Framework Control / Reference Relevance
NIST CSF 2.0 RC.RP-01 — Recovery Plan Execution Shadow copies directly support recovery execution after destructive events.
RC.RP-02 — Recovery Communications Snapshot loss changes how recovery and restoration coordination must be managed.
RC.IM-01 — Improvements Are Identified from Recovery Activities Snapshot failures reveal gaps in resilience and backup design.
Recommendation — Test restoration paths that include shadow copies and confirm recovery works under ransomware scenarios. Define recovery communications that account for loss of local rollback points and slower restore paths. Use failed or weakened shadow-copy recovery to drive backup and resilience improvements.
NIST SP 800-53 Rev 5 CP-9 — System Backup Shadow copies are a backup and restore mechanism used to preserve recoverable data states.
CP-10 — System Recovery and Reconstitution The term is about restoring systems and files from recoverable snapshots.
SC-28 — Protection of Information at Rest Snapshot data at rest needs protection when it contains recoverable production data.
Recommendation — Ensure backups are protected independently of production systems and are routinely tested for restore. Validate recovery procedures that reconstitute files or systems from snapshot-based restore points. Protect snapshot data with controls that limit unauthorized access and tampering.
CIS Controls v8 CIS-11 — Data Recovery Shadow Volume Copies are directly about restore capability and recovery resilience.
CIS-4 — Secure Configuration of Enterprise Assets and Software Snapshot services and permissions depend on secure Windows configuration.
Recommendation — Maintain recoverable backups and test restoration from protected copies. Harden snapshot-related services and permissions so attackers cannot disable or erase them easily.

Practitioner Guidance

What to watch for: Treat shadow copies as a recovery convenience layer that still needs independent backup design. Keep restore points isolated from the systems they protect, and assume that local snapshot data is vulnerable whenever the production host is compromised.

Practitioner takeaway: If an attacker can reach the machine, the safest assumption is that local recovery data is at risk too, so resilient restore options must live outside the same compromise boundary.