Suspicious Volume Shadow Copy Deletion
Detects attempts to delete volume shadow copies using 'vssadmin' or 'wmic shadowcopy' commands. Adversaries often delete shadow copies to prevent system recovery and hinder forensic analysis, especially during ransomware attacks or data destruction efforts.
Microsoft Sentinel (KQL)

