CRPx0 Pre-Encryption Shadow Copy and Backup Destruction
Detects pre-encryption activity typical of the CRPx0 ransomware, involving the destruction of Windows Volume Shadow Copies, Windows Backup Catalogs, or macOS Time Machine snapshots using system utilities such as vssadmin, wbadmin, wmic, or tmutil. This behavior is indicative of an imminent encryption phase.
YARA-L

