Medusa Ransomware Shadow Copy Deletion and Recovery Disable - Storm-1175

This rule detects activities aimed at inhibiting system recovery by identifying attempts to delete volume shadow copies via vssadmin, wmic, or powershell, in combination with disabling windows recovery mode using bcdedit. This behavior is indicative of ransomware preparation, where an adversary attempts to prevent the restoration of data before encryption.