Windows Process Command-Line Indicators of BlackByte Ransomware Activity

Flags Windows process creation command-line patterns consistent with BlackByte ransomware techniques.

FreeReviewedSigma · High · v5
Product
windows
Category
process_creation
Author
Florian Roth (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2022-02-25
Updated
2026-07-31

ATT&CK techniques

Execution → Impact
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Persistence

  5. Priv Esc

  6. Cred Access

  7. Discovery

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

What it detects

This rule flags Windows process creation events where the command line matches specific patterns associated with BlackByte ransomware behavior, including command-line options and script-based actions. Such activity matters because it can indicate attempts to execute malicious commands, disable or remove components, and launch decoy or helper processes. The detection relies on telemetry from Windows process creation, specifically the Image path prefix and CommandLine substrings.

Related detections9 linkedT1059.001 — drag to rearrange
Hidden PowerShell Archive Extraction via ExtractToDirectory
CastleLoader ClickFix PowerShell Hex Decode and Re-Execution
PowerShell Base64 Download Cradle via FromBase64String and Invoke-Expression (via ps_script)
PowerShell CommandLine Uses FromBase64String to Decode Base64 Content (Windows)
PowerShell FromBase64String CommandLine Base64 Encoded Usage (Windows)
Suspicious XOR-Encoded PowerShell Command Line (Windows Process Creation)
Suspicious Shell Command Obfuscation via printf Escape Encoding on VMware ESXi (via process_creation)
Suspicious Script Interpreter Spawned by Explorer via ClickFix Run Dialog (via process_creation)
Suspicious PowerShell Download Cradle via ClickFix Fake CAPTCHA (via process_creation)
Windows Process Command-Line Indicators of BlackByte Ransomware Activity
Pivot detection · T1059.001 · 9 related

Changelog

v5
  1. v5
    Candidate ingested via manual entry.2026-07-31
  2. v4
    Candidate ingested via manual entry.2026-07-31
  3. v3
    Candidate ingested via manual entry.2026-07-31
  4. v2
    Candidate ingested via manual entry.2026-07-31
  5. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.