Shadow Copy Deletion via WMIC/vssadmin (Ransomware Recovery Inhibition)
Detects the use of native Windows tools like vssadmin and wmic to delete Volume Shadow Copies. This activity is a common indicator of ransomware or other destructive attacks attempting to inhibit system recovery.
CQL

