Ransomware Pre-Encryption: Shadow Copy and Backup Deletion

Detects the execution of native Windows utilities (vssadmin, wbadmin, bcdedit, diskshadow) configured to delete volume shadow copies, remove backup catalogs, or disable automatic recovery features. This activity is a common indicator of ransomware preparation to prevent data recovery.