Shadow Copy Deletion via WMIC or vssadmin Pre-Encryption (T1490)
Detects the use of native system utilities including wmic, vssadmin, and wbadmin to delete Volume Shadow Copies or the Backup Catalog, as well as the deletion of local snapshots on macOS via tmutil. These actions are common techniques employed by ransomware to prevent system restoration after encryption.
Cortex XDR

