Shadow Copy Deletion via PowerShell, vssadmin, or WMIC - T1490

Detects the deletion of volume shadow copies using standard Windows utilities such as vssadmin.exe, wmic.exe, or PowerShell commands. This behavior is commonly associated with ransomware or other malicious activity aimed at inhibiting system recovery by removing backups.