Reported BINDCLOAK Encrypted Payload File Event
Detects file telemetry for the exact encrypted payload filename shown in the attack-flow image. It covers the file IOC, not the decryption or reflective loading behavior.
PaidUnreviewedSigmahighv1
Full detection rule
Unlock this rule to view and copy it
The detection logic is included with a plan. Everything else — context, mappings and implementation details — stays free on this page.
What it detects
Detects a Windows file event involving the reported encrypted payload filename used before BINDCLOAK loading.
Prerequisites and telemetry
Requires Windows file event telemetry with TargetFilename populated for file create, modify, rename, or similar file activity.
Limitations
Generic file events do not prove whether the file was created, read, decrypted, or reflectively loaded unless the deployed sensor provides those action fields. The rule may also match defensive handling of the same sample name.
Known false positives
- Malware analysis, quarantine, backup, or incident response systems storing the exact reported filename
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.