Ransomware Pre-Encryption Shadow Copy Deletion T1490

This rule detects attempts to delete Volume Shadow Copies (VSS) using native Windows utilities such as vssadmin, WMIC, or PowerShell. Attackers commonly perform this action to inhibit system recovery and prevent the restoration of data, often as a precursor or during the impact phase of ransomware attacks.