Shadow Copy Deletion (Ransomware Indicator)
Detects attempts to delete Volume Shadow Copies using 'vssadmin' or 'wmic' commands, which is a common tactic used by ransomware to prevent system recovery.
Microsoft Sentinel (KQL)

Detects attempts to delete Volume Shadow Copies using 'vssadmin' or 'wmic' commands, which is a common tactic used by ransomware to prevent system recovery.

Already have an account?