Skip to content

Hide Navigation Hide TOC

UEFI Persistence Via Wpbbin - ProcessCreation (4abc0ec4-db5a-412f-9632-26659cddf145)

Detects execution of the binary "wpbbin" which is used as part of the UEFI based persistence method described in the reference section

Cluster A Galaxy A Cluster B Galaxy B Level
UEFI Persistence Via Wpbbin - ProcessCreation (4abc0ec4-db5a-412f-9632-26659cddf145) Sigma-Rules System Firmware - T1542.001 (16ab6452-c3c1-497c-a47d-206018ca1ada) Attack Pattern 1
System Firmware - T1542.001 (16ab6452-c3c1-497c-a47d-206018ca1ada) Attack Pattern Pre-OS Boot - T1542 (7f0ca133-88c4-40c6-a62f-b3083a7fbc2e) Attack Pattern 2