Ransomware Series: Shadow Copy & Backup Deletion via vssadmin/wbadmin/wmic/bcdedit

This rule detects the execution of common Windows administration utilities (vssadmin.exe, wmic.exe, wbadmin.exe, bcdedit.exe) being used to delete Volume Shadow Copies, backup catalogs, or modify boot configuration data to disable automatic recovery. These actions are frequently performed by ransomware to prevent data restoration.