Ransomware Pre-Encryption: Shadow Copy and Backup Deletion
Detects the execution of native Windows utilities (vssadmin, wbadmin, bcdedit, diskshadow) configured to delete volume shadow copies, remove backup catalogs, or disable automatic recovery features. This activity is a common indicator of ransomware preparation to prevent data recovery.
SentinelOne

