Volume Shadow Copy Deletion via vssadmin, wmic, or PowerShell
Detects the deletion of Windows Volume Shadow Copies using vssadmin.exe, wmic.exe, or PowerShell (WMI/CIM objects). This activity is commonly used by ransomware to prevent local data recovery by destroying shadow copy backups before encryption.
Sigma

