LockBit (Bitwise Spider/Gold Mystic) Shadow Copy Deletion Pre-Encryption

Detects attempts to inhibit system recovery by deleting Volume Shadow Copies or modifying Windows Boot Configuration Data, a technique commonly employed by LockBit and other ransomware families prior to file encryption.