Shadow Copy/Backup Catalog Tampering Preceding Ransomware
Detects attempts to inhibit system recovery by deleting volume shadow copies or modifying backup/boot recovery configurations. The rule monitors for the execution of vssadmin, wmic, wbadmin, and bcdedit with flags known to facilitate system recovery inhibition, often observed as a precursor to ransomware activity.
Microsoft Sentinel (KQL)

