Umbra Wiki technique technique/T1518.002
Back to wiki

T1518.002 — Backup Software Discovery

provenance: imported · ATT&CK: T1518.002

T1518.002: Backup Software Discovery

MITRE ATT&CK® Enterprise technique

Tactics Discovery
Platforms Windows, macOS, Linux
Permissions required
Version 1.0
Parent technique T1518

Description

Adversaries may attempt to get a listing of backup software or configurations that are installed on a system. Adversaries may use this information to shape follow-on behaviors, such as Data Destruction, Inhibit System Recovery, or Data Encrypted for Impact.

Commands that can be used to obtain security software information are netsh, reg query with Reg, dir with cmd, and Tasklist, but other indicators of discovery behavior may be more specific to the type of software or security system the adversary is looking for, such as Veeam, Acronis, Dropbox, or Paragon.(Citation: Symantec Play Ransomware 2023)

Detection

(no detection guidance published)

Data sources

  • (none listed)

References

  • ATT&CK page: https://attack.mitre.org/techniques/T1518/002
  • ATT&CK Enterprise matrix: https://attack.mitre.org/matrices/enterprise/