Windows File Decryption via Gpg4win (gpg.exe/gpg2.exe with passphrase prompt)

Identifies Windows Gpg4win (gpg.exe/gpg2.exe) decryption commands that include a passphrase keyword.

FreeReviewedSigma · Medium · v2
Product
windows
Category
process_creation
Author
Nasreddine Bencherchali (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2023-08-09
Updated
2026-07-31

What it detects

This rule identifies process creation events where Gpg4win’s OpenPGP executables (gpg.exe or gpg2.exe) are used with command-line flags indicating file decryption and a passphrase-related prompt. Attackers may use Gpg4win to decrypt protected payloads or artifacts before execution, making this a useful indicator of potential staging or execution preparation. Detection relies on Windows process creation telemetry capturing the executable path, its description, and the command-line parameters.

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.