Reported BINDCLOAK Encrypted Payload File Event

Detects file telemetry for the exact encrypted payload filename shown in the attack-flow image. It covers the file IOC, not the decryption or reflective loading behavior.

PremiumReviewedSigma · High · v1
Product
windows
Category
file_event
Author
HuntRule
Published
2026-07-30
Updated
2026-07-30

What it detects

Detects a Windows file event involving the reported encrypted payload filename used before BINDCLOAK loading.

Prerequisites and telemetry

Requires Windows file event telemetry with TargetFilename populated for file create, modify, rename, or similar file activity.

Limitations

Generic file events do not prove whether the file was created, read, decrypted, or reflectively loaded unless the deployed sensor provides those action fields. The rule may also match defensive handling of the same sample name.

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.