Akira Ransomware VSS Deletion via WMIC/PowerShell (Bumblebee/AdaptixC2)
Detects the deletion of Volume Shadow Copies using native Windows utilities like WMIC or PowerShell cmdlets (Get-WmiObject, Get-CimInstance) targeting Win32_ShadowCopy. This behavior is a common indicator of ransomware preparation to inhibit system recovery prior to encryption, as observed in attacks involving the Akira ransomware.
Sigma

