Inhibit System Recovery via REAGENTC and WBADMIN
This rule detects the execution of 'REAGENTC.EXE' with the '/disable' argument and 'WBADMIN.EXE' with 'delete catalog -quiet' within a 10-minute window on the same device. This combination of commands is indicative of an adversary attempting to inhibit system recovery by disabling Windows Recovery Environment and deleting the Windows Backup Catalog, often seen in ransomware attacks.
Microsoft Sentinel (KQL)

