This website uses cookies to ensure you get the best experience.
Got it!
Register
|
Login
Menu
Home
Sigma Rules
Splunk Rules
Explore Rules
Analytic Stories
MITRE ATT&CK
Overview
Matrix
Techniques
Groups
Software
Campaigns
Search
About
File Recovery From Backup Via Wbadmin.EXE
Original Source:
[Sigma source]
Title:
File Recovery From Backup Via Wbadmin.EXE
Status:
test
Description:
Detects the recovery of files from backups via "wbadmin.exe". Attackers can restore sensitive files such as NTDS.DIT or Registry Hives from backups in order to potentially extract credentials.
References:
-https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/wbadmin-start-recovery
-https://lolbas-project.github.io/lolbas/Binaries/Wbadmin/
Author:
Nasreddine Bencherchali (Nextron Systems), frack113
Date:
2024-05-10
modified:
None
Tags:
-'attack.impact'
-'attack.t1490'
Logsource:
category: process_creation
product: windows
Detection:
selection_img:
Image|endswith
:
'\wbadmin.exe'
OriginalFileName
:
'WBADMIN.EXE'
selection_cli:
CommandLine|contains|all
:
-' recovery'
-'recoveryTarget'
-'itemtype:File'
condition
:
all of selection_*
Falsepositives:
-Unknown
Level:
medium