Reported BINDCLOAK Encrypted Payload File Event

Detects file telemetry for the exact encrypted payload filename shown in the attack-flow image. It covers the file IOC, not the decryption or reflective loading behavior.

PaidUnreviewedSigmahighv1
Full detection rule

Unlock this rule to view and copy it

The detection logic is included with a plan. Everything else — context, mappings and implementation details — stays free on this page.

What it detects

Detects a Windows file event involving the reported encrypted payload filename used before BINDCLOAK loading.

Prerequisites and telemetry

Requires Windows file event telemetry with TargetFilename populated for file create, modify, rename, or similar file activity.

Limitations

Generic file events do not prove whether the file was created, read, decrypted, or reflectively loaded unless the deployed sensor provides those action fields. The rule may also match defensive handling of the same sample name.

Known false positives

  • Malware analysis, quarantine, backup, or incident response systems storing the exact reported filename

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.