Ransomware Precursor — Shadow Copy / Backup Deletion
Detects the use of native Windows utilities such as vssadmin, wbadmin, wmic, diskshadow, and bcdedit to delete volume shadow copies, backup catalogs, or modify boot configuration to prevent system recovery. The rule explicitly excludes designated backup servers to reduce noise from legitimate management activities.
Microsoft Sentinel (KQL)

