Shadow Copy Deletion via Multiple Non-Standard Binaries
Detects the deletion of volume shadow copies using common Windows administrative utilities including vssadmin.exe, wmic.exe, diskshadow.exe, or through PowerShell WMI/CIM cmdlets. This behavior is frequently associated with ransomware and data destruction attacks aiming to prevent system recovery.
Microsoft Sentinel (KQL)

