mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
3.7 KiB
3.7 KiB
title, excerpt, categories, last_modified_at, toc, toc_label, tags
| title | excerpt | categories | last_modified_at | toc | toc_label | tags | |||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| WBAdmin Delete System Backups | Inhibit System Recovery |
|
2021-01-22 | true |
|
Try in Splunk Security Cloud{: .btn .btn--success}
Description
This search looks for flags passed to wbadmin.exe (Windows Backup Administrator Tool) that delete backup files. This is typically used by ransomware to prevent recovery.
- Type: TTP
- Product: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud
- Datamodel: Endpoint
- Last Updated: 2021-01-22
- Author: Michael Haag, Splunk
- ID: cd5aed7e-5cea-11eb-ae93-0242ac130002
ATT&CK
| ID | Technique | Tactic |
|---|---|---|
| T1490 | Inhibit System Recovery | Impact |
Search
| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name=wbadmin.exe Processes.process="*delete*" AND (Processes.process="*catalog*" OR Processes.process="*systemstatebackup*") by Processes.process_name Processes.process Processes.parent_process_name Processes.dest Processes.user
| `drop_dm_object_name(Processes)`
| `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)`
| `wbadmin_delete_system_backups_filter`
Associated Analytic Story
How To Implement
You must be ingesting endpoint data that tracks process activity, including parent-child relationships from your endpoints to populate the Endpoint data model in the Processes node. Tune based on parent process names.
Required field
- _time
- Processes.process_name
- Processes.process
- Processes.parent_process_name
- Processes.dest
- Processes.user
Kill Chain Phase
- Actions on Objectives
Known False Positives
Administrators may modify the boot configuration.
RBA
| Risk Score | Impact | Confidence | Message |
|---|---|---|---|
| 15.0 | 30 | 50 | System backups deletion on dest |
Reference
- https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1490/T1490.md
- https://thedfirreport.com/2020/10/08/ryuks-return/
- https://attack.mitre.org/techniques/T1490/
- https://docs.microsoft.com/en-us/windows-server/administration/windows-commands/wbadmin
Test Dataset
Replay any dataset to Splunk Enterprise by using our replay.py tool or the UI.
Alternatively you can replay a dataset into a Splunk Attack Range
source | version: 1