Unauthorized Access to Acronis Backup Data After Privilege Escalation
Detects file-related operations (creation, modification, renaming, or deletion) performed on files containing 'acronis' or 'backup' in their path, executed by a process associated with Acronis, running under highly privileged system contexts (root or SYSTEM). This activity is indicative of potential unauthorized manipulation or disabling of backup software, commonly seen in ransomware attacks to inhibit recovery.
Cortex XDR

