Ransomware Backup Agent Termination via System Tools (T1489/T1490)

Detects the use of common Windows system administration tools (cmd, powershell, net, sc, taskkill, wmic) to stop, delete, or terminate known backup software agents. This behavior is highly characteristic of ransomware or destructive attacks attempting to inhibit system recovery by destroying backup infrastructure.