Hunting For Shadow Copy Deletion
mukul975/Anthropic-Cybersecurity-Skills
Runs a hypothesis-driven threat hunt for Volume Shadow Copy deletion (T1490) by querying SIEM/EDR telemetry for vssadmin, wmic shadowcopy, and PowerShell shadow-copy-deletion commands.
