Windows UEFI Persistence: Detect wpbbin.exe Execution

Alerts on execution of C:\Windows\System32\wpbbin.exe, a potential indicator of UEFI persistence on Windows.

FreeReviewedSigma · High · v1
Product
windows
Category
process_creation
Author
Nasreddine Bencherchali (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2022-07-18
Updated
2026-07-30

ATT&CK techniques

Persistence → Defense Evasion
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Priv Esc

  6. Cred Access

  7. Discovery

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule flags process creation events where the executable C:\Windows\System32\wpbbin.exe is run. Attackers may use wpbbin as part of UEFI-based persistence to maintain execution after reboot. It relies on Windows process creation telemetry that records the full image path for started processes.

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.