Akira Ransomware VSS Deletion via WMIC/PowerShell (Bumblebee/AdaptixC2)

Detects the deletion of Volume Shadow Copies using native Windows utilities like WMIC or PowerShell cmdlets (Get-WmiObject, Get-CimInstance) targeting Win32_ShadowCopy. This behavior is a common indicator of ransomware preparation to inhibit system recovery prior to encryption, as observed in attacks involving the Akira ransomware.