Windows UEFI Persistence Indicator: Creation of C:\Windows\System32\wpbbin.exe

Flags creation of C:\Windows\System32\wpbbin.exe, a potential UEFI persistence artifact.

FreeReviewedSigma · High · v2
Product
windows
Category
file_event
Author
Nasreddine Bencherchali (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2022-07-18
Updated
2026-07-31

ATT&CK techniques

Persistence → Defense Evasion
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Priv Esc

  6. Cred Access

  7. Discovery

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule identifies creation of the file C:\Windows\System32\wpbbin.exe, a behavior that may indicate an attempt to establish UEFI-based persistence. Attackers may choose this location and filename to place an executable associated with low-level firmware persistence mechanisms. The detection relies on Windows file-creation telemetry that records the target filename and path.

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.