Delete Volume Shadow Copies via WMI with PowerShell - PS Script (e17121b4-ef2a-4418-8a59-12fb1631fa9e)
Deletes Windows Volume Shadow Copies with PowerShell code and Get-WMIObject. This technique is used by numerous ransomware families such as Sodinokibi/REvil