This website uses cookies to ensure you get the best experience.
Got it!
Register
|
Login
Menu
Home
Sigma Rules
Splunk Rules
Explore Rules
Analytic Stories
MITRE ATT&CK
Overview
Matrix
Techniques
Groups
Software
Campaigns
Search
About
PUA - Restic Backup Tool Execution
Original Source:
[Sigma source]
Title:
PUA - Restic Backup Tool Execution
Status:
experimental
Description:
Detects the execution of the Restic backup tool, which can be used for data exfiltration. Threat actors may leverage Restic to back up and exfiltrate sensitive data to remote storage locations, including cloud services. If not legitimately used in the enterprise environment, its presence may indicate malicious activity.
References:
-https://thedfirreport.com/2024/09/30/nitrogen-campaign-drops-sliver-and-ends-with-blackcat-ransomware/#exfiltration
-https://restic.net/
-https://restic.readthedocs.io/en/stable/030_preparing_a_new_repo.html
Author:
Nounou Mbeiri, Swachchhanda Shrawan Poudel (Nextron Systems)
Date:
2025-10-17
modified:
None
Tags:
-'attack.exfiltration'
-'attack.t1048'
-'attack.t1567.002'
Logsource:
product: windows
category: process_creation
Detection:
selection_specific:
- CommandLine|contains|all
:
- '--password-file'
- 'init'
- ' -r '
- CommandLine|contains|all
:
- '--use-fs-snapshot'
- 'backup'
- ' -r '
selection_restic:
CommandLine|contains
:
-'sftp:'
-'rest:http'
-'s3:s3.'
-'s3.http'
-'azure:'
-' gs:'
-'rclone:'
-'swift:'
-' b2:'
CommandLine|contains|all
:
-' init '
-' -r '
condition
:
1 of selection_*
Falsepositives:
-Legitimate use of Restic for backup purposes within the organization.
Level:
high