Files
splunk-security_content/docs/_posts/2021-12-07-wbadmin_delete_system_backups.md
2021-12-09 13:51:31 -05:00

4.1 KiB

title, excerpt, categories, last_modified_at, toc, toc_label, tags
title excerpt categories last_modified_at toc toc_label tags
WBAdmin Delete System Backups Inhibit System Recovery
Endpoint
2021-12-07 true
Inhibit System Recovery
Impact
Splunk Behavioral Analytics
Endpoint_Processes

Try in Splunk Security Cloud{: .btn .btn--success}

Description

This search looks for flags passed to wbadmin.exe (Windows Backup Administrator Tool) that delete backup files. This is typically used by ransomware to prevent recovery.

  • Type: TTP
  • Product: Splunk Behavioral Analytics
  • Datamodel: Endpoint_Processes
  • Last Updated: 2021-12-07
  • Author: Michael Haag, Splunk
  • ID: 71efbf52-4dbb-4c00-a520-306aa546cbb7

ATT&CK

ID Technique Tactic
T1490 Inhibit System Recovery Impact

| from read_ssa_enriched_events() 
| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=lower(ucast(map_get(input_event, "process"), "string", null)), process_name=lower(ucast(map_get(input_event, "process_name"), "string", null)), process_path=ucast(map_get(input_event, "process_path"), "string", null), parent_process_name=ucast(map_get(input_event, "parent_process_name"), "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) 
| where cmd_line IS NOT NULL AND process_name IS NOT NULL AND process_name="wbadmin.exe" AND like (cmd_line, "%delete%") OR like (cmd_line, "%catalog%") OR like (cmd_line, "%systemstatebackup%") 
| eval start_time=timestamp, end_time=timestamp, entities=mvappend(ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line, "process_name", process_name, "parent_process_name", parent_process_name, "process_path", process_path]) 
| into write_ssa_detected_events();

Associated Analytic Story

How To Implement

To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the Endpoint_Processess datamodel.

Required field

  • _time
  • dest_device_id
  • process_name
  • parent_process_name
  • process_path
  • dest_user_id
  • process
  • cmd_line

Kill Chain Phase

  • Exploitation

Known False Positives

Administrators may modify the boot configuration.

RBA

Risk Score Impact Confidence Message
15.0 30 50 An instance of parent_process_name spawning process_name was identified on endpoint dest_device_id by user dest_user_id attempting to delete system backups.

Reference

Test Dataset

Replay any dataset to Splunk Enterprise by using our replay.py tool or the UI. Alternatively you can replay a dataset into a Splunk Attack Range

source | version: 1