Actors will attempt to delete backups with vssadmin when deploying ransomware.
C:\System Volume
Find Windows Event IDs in this folder.
C:\Windows\System32\winevt\Logs
Last updated 3 years ago