Mass file modification burst followed by shadow-copy/backup deletion

Detects a sequence of activity indicative of destructive ransomware or wiper behavior on a Windows device. The rule correlates a high volume of file modification, creation, or rename events within a short timeframe with concurrent attempts to delete or modify Windows backup and recovery mechanisms (such as Volume Shadow Copies or Boot Configuration Data) using native administrative utilities.