Ransomware Shadow Copy Deletion via WMIC ShadowCopy Delete
Detects the use of the Windows Management Instrumentation Command-line (WMIC) utility to delete individual Volume Shadow Copy (VSS) snapshots. This technique is commonly used by ransomware families to inhibit system recovery by preventing users from restoring files from shadow copies.
YARA-L

