UEFI Persistence Via Wpbbin - ProcessCreation

 Original Source: [Sigma source]
Title: UEFI Persistence Via Wpbbin - ProcessCreation
Status: test
Description:Detects execution of the binary "wpbbin" which is used as part of the UEFI based persistence method described in the reference section
References:
  -https://grzegorztworek.medium.com/using-uefi-to-inject-executable-files-into-bitlocker-protected-drives-8ff4ca59c94c
  -https://persistence-info.github.io/Data/wpbbin.html
Author: Nasreddine Bencherchali (Nextron Systems)
Date: 2022-07-18
modified:None
Tags:
  • -'attack.persistence'
  • -'attack.stealth'
  • -'attack.t1542.001'
Logsource:
  • product: windows
  • category: process_creation
Detection:
  selection:
    Image: 'C:\Windows\System32\wpbbin.exe'
  condition:selection
Falsepositives:
  -Legitimate usage of the file by hardware manufacturer such as lenovo (Thanks @0gtweet for the tip)
Level: high