Skip to content

Hide Navigation Hide TOC

UEFI Persistence Via Wpbbin - FileCreation (e94b9ddc-eec5-4bb8-8a58-b9dc5f4e185f)

Detects creation of a file named "wpbbin" in the "%systemroot%\system32\" directory. Which could be indicative of UEFI based persistence method

Cluster A Galaxy A Cluster B Galaxy B Level
System Firmware - T1542.001 (16ab6452-c3c1-497c-a47d-206018ca1ada) Attack Pattern UEFI Persistence Via Wpbbin - FileCreation (e94b9ddc-eec5-4bb8-8a58-b9dc5f4e185f) Sigma-Rules 1
System Firmware - T1542.001 (16ab6452-c3c1-497c-a47d-206018ca1ada) Attack Pattern Pre-OS Boot - T1542 (7f0ca133-88c4-40c6-a62f-b3083a7fbc2e) Attack Pattern 2