Portable Gpg.EXE Execution (77df53a5-1d78-4f32-bc5a-0e7465bd8f41)
Detects the execution of "gpg.exe" from uncommon location. Often used by ransomware and loaders to decrypt/encrypt data.
Cluster A | Galaxy A | Cluster B | Galaxy B | Level |
---|---|---|---|---|
Portable Gpg.EXE Execution (77df53a5-1d78-4f32-bc5a-0e7465bd8f41) | Sigma-Rules | Data Encrypted for Impact - T1486 (b80d107d-fa0d-4b60-9684-b0433e8bdba0) | Attack Pattern | 1 |