Qilin Ransomware Shadow Deletion + Rapid Multi-Dir File Writes (T1486,T1490)
Detects the deletion of volume shadow copies using standard Windows utilities like vssadmin.exe or wmic.exe, combined with concurrent file activity in multiple directories, a behavior frequently observed during the impact phase of a ransomware attack (specifically associated with the Qilin ransomware family).
Splunk (SPL)

