When this fires, the first question is whether the account and parent process belong to a sanctioned backup or imaging workflow. If they do, confirm the schedule and close it. If they do not, read the command line: /all, delete shadows, delete catalog, or bcdedit recovery flags all mean the whole recovery surface, not a single snapshot. Then pull the host's last 15 minutes, new service creations, PsExec or remote execution, mass file writes, and ransom-note filenames, to see how far along the intrusion already is.
Bulk /all deletion by anything outside your backup stack is a detonation precursor. Escalate it as an active ransomware event, not a maintenance false positive, and do it now rather than after more triage. Recovery inhibition typically runs seconds to minutes ahead of encryption, so isolate the host from the network immediately: pulling it can stop the payload spreading to file shares and other machines before it finishes. Keep the host powered on and preserved for IR instead of reimaging, since the volatile state is your best lead on entry point and scope.