Windows: Detect SysAid user.exe Loader Execution by Filename and SHA256 Hash

Flags execution of a specific SysAid-hosted Windows binary when the process image path and SHA256 match.

FreeReviewedSigma · High · v5
Product
windows
Category
process_creation
Author
Nasreddine Bencherchali (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2023-11-09
Updated
2026-07-31

What it detects

This rule identifies execution of a specific SysAid Server Tomcat webapp binary by matching its full filename and a known SHA256 hash. Such targeted loader execution is a key step in delivering additional malicious payloads, so reliably detecting it can expose early compromise activity. Telemetry relies on Windows process creation events that include both the executed image path and the file hash.

Changelog

v5
  1. v5
    Candidate ingested via manual entry.2026-07-31
  2. v4
    Candidate ingested via manual entry.2026-07-31
  3. v3
    Candidate ingested via manual entry.2026-07-31
  4. v2
    Candidate ingested via manual entry.2026-07-31
  5. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.