Windows: Suspicious Child Process Execution by Notepad++ Updater (gup.exe)

Alerts when Notepad++ gup.exe spawns command/scripting or utility processes using suspicious tool keywords on Windows.

FreeReviewedSigma · High · v2
Product
windows
Category
process_creation
Author
Swachchhanda Shrawan Poudel (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2026-02-03
Updated
2026-07-31

ATT&CK techniques

Initial Access → Collection
  1. Recon

  2. Resource Dev

  3. Execution

  4. Persistence

  5. Priv Esc

  6. Defense Evasion

  7. Discovery

  8. Lateral Movement

  9. C2

  10. Exfiltration

  11. Impact

What it detects

This rule flags Windows process creation events where the Notepad++ updater binary (gup.exe) spawns a suspicious child process. It focuses on child images commonly used for command execution and script handling (cmd.exe, powershell.exe/pwsh, cscript/wscript, mshta.exe) and CLI patterns associated with common download or execution tooling (bitsadmin, certutil, curl, wget, regsvr32, rundll32, forfiles, etc.). This matters because abused updaters can use spawned processes to execute or stage unwanted payloads; the detection relies on process creation telemetry including parent image, child image, and command line.

Related detections9 linkedT1195.002 — drag to rearrange
Windows File Creation by Notepad++ Updater gup.exe in Uncommon Locations
Windows DNS Monitoring: gup.exe Queries to Uncommon Domains
Suspicious Child Process Spawned by Python Interpreter via Process Creation
Suspicious npm Postinstall Node Execution From Fixtures Path (BeaverTail OtterCookie)
Malicious Evilginx AiTM Phishing Proxy Default TLS Certificate
Suspicious TrueConf Update Chain Spawning Temporary Executable in Operation TrueChaos
Malicious TeamPCP durabletask Payload python3 managed.pyz from tmp (via process_creation)
Suspicious Sneaky 2FA Phishing Kit License Check via API Key Endpoint (via proxy)
Malicious PowerShell Download from bullethost.cloud Staging Server
Windows: Suspicious Child Process Execution by Notepad++ Updater (gup.exe)
Pivot detection · T1195.002 · 9 related

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.