Ransomware Shadow Copy Deletion via vssadmin, wmic, or PowerShell (T1490)
Detects the deletion of volume shadow copies using standard Windows utilities such as vssadmin.exe, wmic.exe, or PowerShell. This behavior is a common indicator of ransomware activity aimed at preventing system recovery.
SentinelOne

