Windows Process Command Line Matching Goofy-Guineapig Backdoor Command Fragment

Alerts on Windows process command lines containing a specific non-interactive choice command often used in automation.

FreeReviewedSigma · High · v5
Product
windows
Category
process_creation
Author
X__Junior (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2023-05-14
Updated
2026-07-31

What it detects

This rule flags Windows process executions whose command line contains the specific fragment "choice /t %d /d y /n >nul" associated with the Goofy-Guineapig backdoor behavior described in the referenced NCSC report. Such timing and prompt-bypass commands can be used to support automated execution or staging in malware workflows. Detection relies on process creation telemetry that includes the full command line for each started process.

Changelog

v5
  1. v5
    Candidate ingested via manual entry.2026-07-31
  2. v4
    Candidate ingested via manual entry.2026-07-31
  3. v3
    Candidate ingested via manual entry.2026-07-31
  4. v2
    Candidate ingested via manual entry.2026-07-31
  5. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.