An organization uses an EDR solution and wants to detect ransomware that encrypts files and then deletes volume shadow copies. Which EDR detection technique would be most effective for this behavior?
Ransomware's destructive sequence — rapid mass file encryption followed by vssadmin.exe deleting shadow copies — is a behavioural pattern, not a signature. Detecting that combination of mass modification and shadow-copy deletion catches the attack regardless of malware family, satisfying the requirement to detect this specific behaviour.
Why this answer
Behavioral detection monitors runtime behavior like file encryption and shadow copy deletion, which are indicative of ransomware.