
Rule Info
Name
File Recovery From Backup Via Wbadmin.EXE
Author
Nasreddine Bencherchali (Nextron Systems), frack113
Description
Detects the recovery of files from backups via "wbadmin.exe".
Attackers can restore sensitive files such as NTDS.DIT or Registry Hives from backups in order to potentially extract credentials.
Date
2024-05-10 00:00:00
Modified
None
Id
6fe4aa1e-0531-4510-8be2-782154b73b48
Tags
attack.impact attack.t1490
Type
Community Rule
Link to Public Repo