Ransomware Pre-Encryption Shadow Copy & Recovery Deletion
Detects the use of built-in Windows utilities (vssadmin, wbadmin, bcdedit) to delete volume shadow copies, clear backup catalogs, or modify boot configuration settings to disable recovery features, which is a common precursor to ransomware encryption.
Splunk (SPL)

