Windows Process Creation: Gpg4win File Encryption via gpg.exe or gpg2.exe

Flags Gpg4win (gpg.exe/gpg2.exe) executions using passphrase-based encryption on Windows.

FreeReviewedSigma · Medium · v2
Product
windows
Category
process_creation
Author
Nasreddine Bencherchali (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2023-08-09
Updated
2026-07-31

What it detects

This rule identifies Windows process executions of Gpg4win’s OpenPGP utilities (gpg.exe or gpg2.exe) when used to encrypt files. Attackers commonly encrypt content to protect data from inspection, hide artifacts, or prepare staged payloads. The detection relies on process creation telemetry including the executable path/name and command-line arguments, specifically the presence of encryption mode and a passphrase reference.

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.