{"id":"T1518.002","name":"Backup Software Discovery","url":"https://attack.mitre.org/techniques/T1518/002","tactics":["discovery"],"platforms":["Windows","macOS","Linux"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0088","stix_id":"x-mitre-detection-strategy--a3bdd6e2-92d3-45db-a486-9f051c68672b","name":"Backup Software Discovery via CLI, Registry, and Process Inspection (T1518.002)","url":"https://attack.mitre.org/detectionstrategies/DET0088","analytics":[{"id":"AN0240","stix_id":"x-mitre-analytic--dbc6d9ca-9502-46a0-a59b-15b050bb539c","name":"Analytic 0240","description":"Defender observes execution of commands like `tasklist`, `sc query`, `reg query`, or PowerShell WMI/Registry queries targeting known backup products (e.g., Veeam, Acronis, CrashPlan). Behavior often includes parent-child lineage involving PowerShell or cmd.exe with discovery syntax, and enumeration of services, directories, or registry paths tied to backup software.","url":"https://attack.mitre.org/detectionstrategies/DET0088#AN0240","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Security","channel":"EventCode=4688","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"wineventlog-security"},{"name":"WinEventLog:Sysmon","channel":"EventCode=13, 14","data_component":"DC0063","data_component_name":"Windows Registry Key Modification","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=11","data_component":"DC0039","data_component_name":"File Creation","log_source_slug":"wineventlog-sysmon"}],"mutable_elements":[{"field":"KnownBackupVendors","description":"List of software vendors to match in command-line or registry queries"},{"field":"UserContextScope","description":"Focus on low-privilege or interactive user contexts rather than service accounts"},{"field":"SuspiciousParentProcesses","description":"Flag execution from scripting tools, interpreters, or LOLBins"}],"live":true,"detection_strategies":["DET0088"],"techniques":["T1518.002"]},{"id":"AN0241","stix_id":"x-mitre-analytic--93918e31-51b1-4d85-8b16-590871c2cc1f","name":"Analytic 0241","description":"Defender observes use of CLI tools (`find`, `grep`, `ls`, `dpkg`, `rpm`, `systemctl`, `ps aux`) to discover backup agents or config files (e.g., rsnapshot, duplicity, veeam). This often includes command lines that recursively search `/etc/`, `/opt/`, or `/var/` directories for keywords like `backup`, and parent-child relationships involving shell or Python scripts.","url":"https://attack.mitre.org/detectionstrategies/DET0088#AN0241","platforms":["Linux"],"log_source_references":[{"name":"auditd:SYSCALL","channel":"execve: Execution of discovery commands targeting backup binaries, processes, or config paths","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"auditd-syscall"},{"name":"auditd:PATH","channel":"Read access to known backup software configuration files (e.g., /etc/rsnapshot.conf, /opt/veeam/config.ini)","data_component":"DC0055","data_component_name":"File Access","log_source_slug":"auditd-path"}],"mutable_elements":[{"field":"BackupConfigPaths","description":"Directory paths and filenames related to backup agents"},{"field":"ToolchainScope","description":"Shells, interpreters, or binaries used by attacker scripts for discovery"}],"live":true,"detection_strategies":["DET0088"],"techniques":["T1518.002"]},{"id":"AN0242","stix_id":"x-mitre-analytic--e3c81570-be1b-48c8-b000-b70173c5c226","name":"Analytic 0242","description":"Defender detects execution of `mdfind`, `launchctl`, or GUI-based enumeration (e.g., `/Applications/Time Machine.app`) along with command-line usage of `find`, `grep`, or `system_profiler` to identify installed backup tools like Time Machine, Carbon Copy Cloner, or Backblaze. Often triggered from Terminal sessions or within post-exploitation scripts.","url":"https://attack.mitre.org/detectionstrategies/DET0088#AN0242","platforms":["macOS"],"log_source_references":[{"name":"macos:unifiedlog","channel":"Process execution logs showing discovery commands like mdfind, system_profiler, or launchctl list","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"macos-unifiedlog"},{"name":"macos:unifiedlog","channel":"Read access to Time Machine plist files or CCC configurations in ~/Library/Preferences/","data_component":"DC0055","data_component_name":"File Access","log_source_slug":"macos-unifiedlog"}],"mutable_elements":[{"field":"InstallLocationScope","description":"Directories or bundles where backup tools are commonly installed"},{"field":"KnownAppPlistPaths","description":"Plist files related to backup software configurations"}],"live":true,"detection_strategies":["DET0088"],"techniques":["T1518.002"]}],"live":true,"version":"1.0","techniques":["T1518.002"]}],"sigma_rules":[],"kev_cves":[],"_built":"2026-08-24 19:45 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}