Windows DNS Monitoring: gup.exe Queries to Uncommon Domains

Alerts when Notepad++ gup.exe generates DNS queries to domains outside the approved set.

FreeReviewedSigma · Medium · v2
Product
windows
Category
dns_query
Author
Swachchhanda Shrawan Poudel (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2026-02-02
Updated
2026-07-31

ATT&CK techniques

Initial Access → Collection
  1. Recon

  2. Resource Dev

  3. Execution

  4. Persistence

  5. Priv Esc

  6. Defense Evasion

  7. Discovery

  8. Lateral Movement

  9. C2

  10. Exfiltration

  11. Impact

What it detects

This rule flags DNS queries made by Notepad++ updater process gup.exe when the queried domain is not among a set of known legitimate update and hosting domains. Unusual DNS resolution can indicate abuse or diversion of the updater’s network behavior for malicious activity. It relies on Windows DNS query telemetry containing the querying process image ending with gup.exe and the DNS QueryName values.

Related detections9 linkedT1195.002 — drag to rearrange
Windows File Creation by Notepad++ Updater gup.exe in Uncommon Locations
Windows: Suspicious Child Process Execution by Notepad++ Updater (gup.exe)
Suspicious Child Process Spawned by Python Interpreter via Process Creation
Suspicious npm Postinstall Node Execution From Fixtures Path (BeaverTail OtterCookie)
Malicious Evilginx AiTM Phishing Proxy Default TLS Certificate
Suspicious TrueConf Update Chain Spawning Temporary Executable in Operation TrueChaos
Malicious TeamPCP durabletask Payload python3 managed.pyz from tmp (via process_creation)
Suspicious Sneaky 2FA Phishing Kit License Check via API Key Endpoint (via proxy)
Malicious PowerShell Download from bullethost.cloud Staging Server
Windows DNS Monitoring: gup.exe Queries to Uncommon Domains
Pivot detection · T1195.002 · 9 related

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.