Ransomware operators stopped bringing their own software years ago. There's no reason to. Every Windows machine ships with everything they need — a utility to delete backup snapshots, a utility to download files from the internet, a scripting engine that can run anything. Signature-based antivirus has no opinion about a legitimate Microsoft tool doing exactly what it was designed to do.
The problem isn't that these tools run. They run constantly, for entirely normal reasons. The problem is that nothing about the file tells you which time was normal. Only the behavior does: what launched it, what it did next, whether it happened on one machine or forty at once.
That distinction is the whole job. Endpoint detection and response records the behavior on every endpoint, flags the patterns that look like an attack in progress, and puts the result in front of someone who can tell the difference between a backup script and the first ten minutes of a ransomware deployment.