DragonForce/CRPx0 Shadow Copy Deletion via WMIC
Detects the deletion of Volume Shadow Copies using the Windows Management Instrumentation Command-line (WMIC) utility. This behavior is commonly observed in ransomware attacks, including those attributed to DragonForce and CRPx0, as a method to inhibit system recovery prior to file encryption.
Sigma

