Pre-Ransomware Shadow Copy and Backup Deletion (T1490)

Detects the use of legitimate Windows administrative tools (vssadmin, wmic, wbadmin, bcdedit, sc, net) to delete volume shadow copies, clear backup catalogs, disable boot recovery options, or stop critical backup and system services. This behavior is highly characteristic of ransomware activity aiming to prevent data restoration and system recovery.