Shadow Copy and Backup Destruction Commands Prior to Encryption
Detects the use of legitimate Windows administrative utilities (vssadmin.exe, wmic.exe, wbadmin.exe) to delete volume shadow copies or backup catalogs. This behavior is a common tactic employed by ransomware actors to inhibit system recovery and prevent restoration of encrypted data.
Sigma

