Medusa Ransomware Shadow Copy Deletion and Recovery Disable - Storm-1175
This rule detects activities aimed at inhibiting system recovery by identifying attempts to delete volume shadow copies via vssadmin, wmic, or powershell, in combination with disabling windows recovery mode using bcdedit. This behavior is indicative of ransomware preparation, where an adversary attempts to prevent the restoration of data before encryption.
Microsoft Sentinel (KQL)

