Ransomware Series: Nova Ransomware Volume Shadow Copy Deletion via vssadmin and

Detects attempts by malicious software to inhibit system recovery by deleting Volume Shadow Copies. The rule monitors for the execution of vssadmin.exe with deletion flags or wmic.exe with shadowcopy deletion commands combined with non-interactive flags, which are common indicators of ransomware preparation.