Windows File Creation by Notepad++ Updater gup.exe in Uncommon Locations

Alerts on file creations by Notepad++ updater gup.exe when the destination path is uncommon or not in allowed locations.

FreeReviewedSigma · High · v2
Product
windows
Category
file_event
Author
Swachchhanda Shrawan Poudel (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2026-02-03
Updated
2026-07-31

ATT&CK techniques

Initial Access → Collection
  1. Recon

  2. Resource Dev

  3. Execution

  4. Persistence

  5. Priv Esc

  6. Defense Evasion

  7. Discovery

  8. Lateral Movement

  9. C2

  10. Exfiltration

  11. Impact

What it detects

This rule flags file creation events where the Notepad++ updater binary (gup.exe) writes to locations that are not typical for standard installation or expected update artifacts. Uncommon target paths can indicate abuse of the updater component to drop unwanted files or stage additional payloads. The detection relies on Windows file event telemetry that includes the creating process image name and the created file path (TargetFilename).

Related detections9 linkedT1195.002 — drag to rearrange
Windows: Suspicious Child Process Execution by Notepad++ Updater (gup.exe)
Windows DNS Monitoring: gup.exe Queries to Uncommon Domains
Suspicious Child Process Spawned by Python Interpreter via Process Creation
Suspicious npm Postinstall Node Execution From Fixtures Path (BeaverTail OtterCookie)
Malicious Evilginx AiTM Phishing Proxy Default TLS Certificate
Suspicious TrueConf Update Chain Spawning Temporary Executable in Operation TrueChaos
Malicious TeamPCP durabletask Payload python3 managed.pyz from tmp (via process_creation)
Suspicious Sneaky 2FA Phishing Kit License Check via API Key Endpoint (via proxy)
Malicious PowerShell Download from bullethost.cloud Staging Server
Windows File Creation by Notepad++ Updater gup.exe in Uncommon Locations
Pivot detection · T1195.002 · 9 related

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.