Shadow Copy Deletion via vssadmin, wmic, or PowerShell

This rule detects attempts to delete Volume Shadow Copies (VSS) using native Windows utilities such as vssadmin.exe, wmic.exe, or PowerShell. Attackers often perform this action during the impact phase to prevent file recovery after ransomware deployment or other data destruction activities.