Windows Process Execution: Restic Backup Tool Command-Line Indicators

Flags Windows executions where Restic is run with repo init/backup flags or remote storage targets.

FreeReviewedSigma · High · v1
Product
windows
Category
process_creation
Author
Nounou Mbeiri, Swachchhanda Shrawan Poudel (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2025-10-17
Updated
2026-07-30

ATT&CK techniques

Exfiltration
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Discovery

  10. Lateral Movement

  11. Collection

  12. C2

  13. Impact

What it detects

This rule identifies execution of the Restic backup tool by matching specific command-line patterns related to repository initialization and backup operations. Restic can be used to stage and exfiltrate sensitive data to remote storage backends, so unexpected usage in an enterprise environment may indicate malicious activity. It relies on Windows process creation telemetry with command-line fields to determine whether Restic is invoked with characteristic arguments and remote repository targets.

Related detections9 linkedT1567.002 — drag to rearrange
Malicious Bulk Data Exfiltration via Rclone (via process_creation)
Data Exfiltration to WebDAV Share via curl Upload
Suspicious ALPHA SPIDER Rclone Exfiltration Tool Masquerading as System Binary (via process_creation)
Malicious GhostLocker2 C2 Communication via HTTP POST (via proxy)
Suspicious Rclone Exfiltration Masquerading as wininit.exe
BITS Payload Downloaded via Commandline (via process_creation)
BITS Payload Downloaded via PowerShell (via powershell)
Rclone SMB Share Exfiltration
Suspicious Data Exfiltration via Rclone to Cloud Storage (via process_creation)
Windows Process Execution: Restic Backup Tool Command-Line Indicators
Pivot detection · T1567.002 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.