Ransomware VSS Deletion via vssadmin/wmic/PowerShell/wbadmin
Detects the use of native Windows utilities (vssadmin, wmic, powershell, wbadmin) to delete volume shadow copies or backup catalogs. This activity is commonly associated with ransomware or destructive attacks attempting to prevent system recovery.
SentinelOne

