Windows PowerShell Recovery and Event Log Tampering

Detects coordinated activity where a PowerShell process executes multiple distinct administrative utilities (such as wevtutil, vssadmin, wbadmin, or bcdedit) to perform destructive actions like clearing event logs, deleting shadow copies, or disabling system recovery settings. This rule uses correlation to identify sequences of at least three distinct commands and utilities, reducing false positives associated with single administrative tasks.