Deletion of Volume Shadow Copies via WMI with PowerShell - PS Script — Detection Rule

Detects deletion of Windows Volume Shadow Copies with PowerShell code and Get-WMIObject. This technique is used by numerous ransomware families such as Sodinokibi/REvil

Read the full analysis on IntelFusions