Azure Site Recovery / Backup lock deletion attempts to inhibit recovery

Detects attempts to delete Azure resource locks protecting Site Recovery or Backup services, followed by credential retrieval (ListKeys) within a one-hour window. This sequence pattern is a strong indicator of an adversary attempting to disable backup protection before potentially destroying data or exfiltrating keys.