A Windows recovery mechanism that preserves point-in-time copies of files and volumes. Ransomware often deletes shadow copies to block restore options, which makes this control a key target in destructive attacks.
Expanded Definition
A volume shadow copy is a point-in-time snapshot of a Windows volume that can be used for recovery after accidental deletion, corruption, or compromise. In operational terms, it is part of a broader backup and restore posture, but it is not a full backup strategy on its own. The concept is most often discussed in incident response, ransomware recovery, and endpoint hardening, where defenders want a fast rollback path for recently changed files or system state. Microsoft describes this capability through Volume Shadow Copy Service, while security teams usually care about whether the snapshots are enabled, protected, and recoverable under attack conditions.
Definitions are consistent at a high level, but usage in the industry is still evolving because some teams treat shadow copies as a resilience control, while others treat them only as an administrative convenience. Under the NIST Cybersecurity Framework 2.0, the relevant question is whether recovery capabilities are available, tested, and protected from tampering. The most common misapplication is assuming shadow copies are a reliable restore mechanism, which occurs when organisations leave them unprotected on endpoints that attackers can enumerate and delete during privilege escalation.
Examples and Use Cases
Implementing shadow copies rigorously often introduces storage and administration overhead, requiring organisations to weigh rapid recovery against the cost of retained snapshots and the risk of exposure if they are not isolated.
- After a user overwrites a critical spreadsheet, an administrator restores the previous version from a local shadow copy instead of relying on a slower backup retrieval process.
- During ransomware response, the security team checks whether shadow copies survive the intrusion and whether attackers have already run deletion commands to remove restore points.
- An endpoint hardening baseline disables unnecessary local administrative access so attackers cannot easily enumerate or purge snapshots after compromising a workstation.
- A recovery test confirms that shadow copies can still be mounted after a system update, validating that rollback options remain usable during routine operations.
- Forensic analysts compare file timelines against snapshot timestamps to understand when encryption or tampering first occurred and which data remains recoverable.
For organisations building a recovery program, shadow copies should be treated as one layer in a wider resilience stack that also includes offline backups, immutable storage, and restoration testing. That framing is consistent with how the NIST Cybersecurity Framework 2.0 approaches recovery outcomes rather than single technologies.
Why It Matters for Security Teams
Shadow copies matter because attackers often target them early in a destructive campaign. If a threat actor can delete local snapshots, they can remove a quick recovery path and increase pressure to pay ransom or accept prolonged downtime. That makes the control operationally important even though it is not a substitute for backup governance, segmentation, or privileged access management. Security teams also need to recognize that snapshot protection depends on who can modify volume settings, what endpoint controls are in place, and whether the recovery process has been exercised under realistic failure conditions.
This concept also intersects with identity and privilege management. In practice, deleting shadow copies usually requires elevated access, so weak privilege governance can turn a recovery feature into a liability. Teams that align recovery controls with NIST Cybersecurity Framework 2.0 recovery and protection outcomes are better positioned to preserve restore options when systems are under attack. Organisations typically encounter the operational importance of volume shadow copy only after ransomware or destructive malware removes their first restore path, at which point the control becomes unavoidable to address.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST CSF 2.0 provides the primary governance reference for this term.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | RC.RP-1 | Recovery planning includes restoring systems and data after an incident, which shadow copies can support. |
Test whether shadow copies speed restoration and fit into your broader incident recovery runbook.
Related resources from NHI Mgmt Group
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on August 19, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org