LockerGoga Ransomware Indicators in Windows Process Command Line

Flags Windows processes with a specific LockerGoga-style command-line argument pattern.

FreeReviewedSigma · Critical · v5
Product
windows
Category
process_creation
Author
Vasiliy Burov, oscd.community (SigmaHQ), DRL 1.1
Published
2020-10-18
Updated
2026-07-31

ATT&CK techniques

Impact
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Discovery

  10. Lateral Movement

  11. Collection

  12. C2

  13. Exfiltration

What it detects

This rule identifies executions whose command line contains a specific argument pattern associated with LockerGoga ransomware activity. Attackers may rely on such command-line parameters to configure input paths, runtime behavior, or IPC-related functionality during encryption. The detection relies on Windows process creation telemetry that captures the full command line for spawned processes.

Related detections9 linkedT1486 — drag to rearrange
Possible Azure Storage Ransomware via Customer-Managed Key Encryption
Malicious Remote Encryptor Execution via WMIC Process Call Create (Chaos Ransomware)
Suspicious CyberLock Ransomware Encrypted File Creation
Rhysida Ransomware Encrypted File Extension Created
Phobos 8Base Ransomware Encrypted File Extension Created
Rhysida Ransomware Note CriticalBreachDetected.pdf Created
Possible Akira Ransomware Note or Encrypted Extension Creation
Malicious Storm-2603 Ransom Note File Creation
Possible Ransomware Note or Encrypted File Extension Creation
LockerGoga Ransomware Indicators in Windows Process Command Line
Pivot detection · T1486 · 9 related

Changelog

v5
  1. v5
    Candidate ingested via manual entry.2026-07-31
  2. v4
    Candidate ingested via manual entry.2026-07-31
  3. v3
    Candidate ingested via manual entry.2026-07-31
  4. v2
    Candidate ingested via manual entry.2026-07-31
  5. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.