BitLocker Abuse via manage-bde.exe — Encryption or Protector Tampering

Detects the execution of manage-bde.exe with command-line arguments designed to enable encryption, disable/delete BitLocker protectors, or modify authentication keys. This pattern is indicative of ransomware abuse, specifically actors attempting to encrypt drives and destroy recovery capabilities, particularly when spawned from scripting or shell environments like PowerShell, CMD, or WMI.