Shadow Copy Deletion via vssadmin or wmic (T1490)

Detects the use of vssadmin.exe or wmic.exe to delete Volume Shadow Copies. This is a common technique used by ransomware and other malware to prevent system recovery and impede incident response efforts.