Windows File Writes from NPPSpy Hacktool: NPPSpy.txt and NPPSpy.dll

Alerts on Windows file events writing NPPSpy.txt or NPPSpy.dll, consistent with credential dumping by the NPPSpy hacktool.

FreeReviewedSigma · High · v2
Product
windows
Category
file_event
Author
Florian Roth (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2021-11-29
Updated
2026-07-31

What it detects

This rule flags file creation or modification events where the target filename ends with NPPSpy.txt or NPPSpy.dll. NPPSpy is a credential-dumping hacktool that can write captured cleartext credentials to a local file, so file artifacts like these are strong indicators of unauthorized access attempts. It relies on Windows file event telemetry that includes the target filename for the write operation.

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.