Shadow Copy Deletion via Multiple Non-Standard Binaries

Detects the deletion of volume shadow copies using common Windows administrative utilities including vssadmin.exe, wmic.exe, diskshadow.exe, or through PowerShell WMI/CIM cmdlets. This behavior is frequently associated with ransomware and data destruction attacks aiming to prevent system recovery.