<<< Hide Navigation Hide TOC >>>
UEFI Persistence Via Wpbbin - ProcessCreation (4abc0ec4-db5a-412f-9632-26659cddf145)
Detects execution of the binary "wpbbin" which is used as part of the UEFI based persistence method described in the reference section
Cluster A![]() |
Galaxy A![]() |
Cluster B![]() |
Galaxy B![]() |
Level![]() |
---|---|---|---|---|
UEFI Persistence Via Wpbbin - ProcessCreation (4abc0ec4-db5a-412f-9632-26659cddf145) | Sigma-Rules | System Firmware - T1542.001 (16ab6452-c3c1-497c-a47d-206018ca1ada) | Attack Pattern | 1 |
Pre-OS Boot - T1542 (7f0ca133-88c4-40c6-a62f-b3083a7fbc2e) | Attack Pattern | System Firmware - T1542.001 (16ab6452-c3c1-497c-a47d-206018ca1ada) | Attack Pattern | 2 |