Ransomware Pre-Encryption Shadow Copy Deletion and Recovery Sabotage Detection
Detects VSS volume shadow copy deletion commands and boot recovery system disabling, standard behavior of modern ransomware prior to mass file encryption to prevent data recovery without paying the ransom