Suspicious Volume Shadow Copy Deletion

Detects attempts to delete volume shadow copies using 'vssadmin' or 'wmic shadowcopy' commands. Adversaries often delete shadow copies to prevent system recovery and hinder forensic analysis, especially during ransomware attacks or data destruction efforts.