Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0088 — Backup Software Discovery via CLI, Registry, and Process Inspection (T1518.002)
DET0088

Backup Software Discovery via CLI, Registry, and Process Inspection (T1518.002)

3 analytic(s) · 1 technique(s) detected

Analytics

3
AN0240 Analytic 0240
Windows

Defender observes execution of commands like `tasklist`, `sc query`, `reg query`, or PowerShell WMI/Registry queries targeting known backup products (e.g., Veeam, Acronis, CrashPlan). Behavior often includes parent-child lineage involving PowerShell or cmd.exe with discovery syntax, and enumeration of services, directories, or registry paths tied to backup software.

WinEventLog:Security EventCode=4688 WinEventLog:Sysmon EventCode=13, 14 WinEventLog:Sysmon EventCode=11
[KnownBackupVendors] List of software vendors to match in command-line or registry queries
[UserContextScope] Focus on low-privilege or interactive user contexts rather than service accounts
[SuspiciousParentProcesses] Flag execution from scripting tools, interpreters, or LOLBins
AN0241 Analytic 0241
Linux

Defender observes use of CLI tools (`find`, `grep`, `ls`, `dpkg`, `rpm`, `systemctl`, `ps aux`) to discover backup agents or config files (e.g., rsnapshot, duplicity, veeam). This often includes command lines that recursively search `/etc/`, `/opt/`, or `/var/` directories for keywords like `backup`, and parent-child relationships involving shell or Python scripts.

auditd:SYSCALL execve: Execution of discovery commands targeting backup binaries, processes, or config paths auditd:PATH Read access to known backup software configuration files (e.g., /etc/rsnapshot.conf, /opt/veeam/config.ini)
[BackupConfigPaths] Directory paths and filenames related to backup agents
[ToolchainScope] Shells, interpreters, or binaries used by attacker scripts for discovery
AN0242 Analytic 0242
macOS

Defender detects execution of `mdfind`, `launchctl`, or GUI-based enumeration (e.g., `/Applications/Time Machine.app`) along with command-line usage of `find`, `grep`, or `system_profiler` to identify installed backup tools like Time Machine, Carbon Copy Cloner, or Backblaze. Often triggered from Terminal sessions or within post-exploitation scripts.

macos:unifiedlog Process execution logs showing discovery commands like mdfind, system_profiler, or launchctl list macos:unifiedlog Read access to Time Machine plist files or CCC configurations in ~/Library/Preferences/
[InstallLocationScope] Directories or bundles where backup tools are commonly installed
[KnownAppPlistPaths] Plist files related to backup software configurations

Detected Techniques

1

Details

MITRE ID
DET0088
STIX ID
x-mitre-detection-strategy--a3bdd6e2-92d3-45db-a486-9f051c68672b
Analytics
3
Techniques Detected
1
By Tactic
Discovery
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.