Windows process activity matching WannaCry executables and ransom note text

Alerts on Windows process creation where WannaCry-related executables and the @Please_Read_Me@.txt command indicator appear.

FreeReviewedSigma · Critical · v5
Product
windows
Category
process_creation
Author
Florian Roth (Nextron Systems), Tom U. @c_APT_ure (collection), oscd.community, Jonhnathan Ribeiro (SigmaHQ), DRL 1.1
Published
2019-01-16
Updated
2026-07-31

ATT&CK techniques

Defense Evasion → Impact
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Cred Access

  8. Collection

  9. C2

  10. Exfiltration

What it detects

This rule matches Windows process creation events where the process image name ends with known WannaCry-associated filenames or contains the substring 'WanaDecryptor'. It also requires the command line to include '@Please_Read_Me@.txt', a characteristic ransom note marker. The combination helps identify attempted ransomware execution and related components using process creation telemetry with image path and command-line fields.

Related detections9 linkedT1490 — drag to rearrange
RedCurl QWCrypt Ransomware Execution with Hyper-V Targeting Flags
Malicious Azure Deletion of Resource Locks and Immutability Policies
Malicious BitLocker Encryption With Shadow Copy Removal via manage-bde (via process_creation)
Malicious Azure Storage and Compute Destruction via Key Listing and Snapshot Deletion
Possible Azure Storage Ransomware via Customer-Managed Key Encryption
Malicious Boot Configuration Set to Safe Mode with Networking via bcdedit
Shadow Copy Deletion via Vssadmin to Inhibit Recovery
Suspicious Symlink Evaluation Enabled via fsutil
Malicious Mass Hyper-V Virtual Machine Shutdown via PowerShell by Kraken Ransomware
Windows process activity matching WannaCry executables and ransom note text
Pivot detection · T1490 · 9 related

Changelog

v5
  1. v5
    Candidate ingested via manual entry.2026-07-31
  2. v4
    Candidate ingested via manual entry.2026-07-31
  3. v3
    Candidate ingested via manual entry.2026-07-31
  4. v2
    Candidate ingested via manual entry.2026-07-31
  5. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.