Volume Shadow Copy/Backup Deletion Preceding Mass File Writes (T1490)

This rule detects potential ransomware activity by correlating the execution of native Windows utilities used to inhibit system recovery (vssadmin, wmic, wbadmin, bcdedit) followed by a high volume of file modification events on the same host within a 15-minute window.