Ransomware Backup Destruction Chain via vssadmin/wbadmin/bcdedit T1490

This rule detects the coordinated execution of multiple Windows command-line utilities (vssadmin, wbadmin, and bcdedit) within a short time frame (60 seconds). These tools are frequently used by ransomware and other malware to delete volume shadow copies, clear backup catalogs, and disable system recovery features, effectively preventing the restoration of the system after a damaging event.