Shadow Copy Deletion via vssadmin.exe or wmic.exe (T1490)
Detects the execution of vssadmin.exe or wmic.exe with command-line arguments intended to delete Volume Shadow Copies. This activity is a common indicator of ransomware or other destructive attacks aiming to inhibit system recovery.
SentinelOne

