Ransomware Precursor — Shadow Copy / Backup Deletion

Detects the use of native Windows utilities such as vssadmin, wbadmin, wmic, diskshadow, and bcdedit to delete volume shadow copies, backup catalogs, or modify boot configuration to prevent system recovery. The rule explicitly excludes designated backup servers to reduce noise from legitimate management activities.