Browse Rules

Search and filter across all detection sources

12,364 rules

elastic high eql

Potential EtherHiding C2 via Curl JSON-RPC Request

Detects when curl or nscurl is spawned by a shell or osascript to make a JSON-RPC request to a blockchain endpoint for command and control purposes. Adversaries may leverage blockchain smart contracts as a covert C2 channel to retrieve commands or payload staging information, as observed in ClickFix campaigns.

elastic high kql

Multiple Alerts Involving a User

This rule uses alert data to determine when multiple different alerts involving the same user are triggered. Analysts can use this to prioritize triage and response, as these users are more likely to be compromised.

elastic high eql

Potential Etherhiding C2 via Blockchain Connection

Detects when a scripting interpreter makes an outbound network connection to an Ethereum blockchain endpoint for command and control purposes. Adversaries may leverage Ethereum blockchain infrastructure as a covert C2 channel to receive commands and exfiltrate data, as observed in campaigns like SleepyDuck malware.

elastic high kql

Potential Entra ID PRT Extraction via BrowserCore

Identifies anomalous execution of BrowserCore.exe, the Windows component used by Chromium-based browsers for native messaging with the Web Account Manager (WAM). Adversaries abuse BrowserCore to extract Entra ID Primary Refresh Tokens (PRTs) without interactive browser context, enabling session hijacking. Legitimate BrowserCore launches carry a chrome-extension:// argument from the browser native-messaging host.

elastic high eql

Potential Masquerading as System32 DLL

Identifies suspicious instances of default system32 DLLs either unsigned or signed with non-MS certificates. This can potentially indicate the attempt to masquerade as system DLLs, perform DLL Search Order Hijacking or backdoor and resign legitimate DLLs.

loldrivers high sigma

Driver Load - 1109.sys

Detects loading of driver 1109.sys via hash. 1109.sys is a vulnerable kernel driver from the KeServiceDescriptorTable/vulnerable-drivers repository. The driver exposes dangerous kernel primitives to usermode.

loldrivers high sigma

Driver Load - 1fc7aeeff3ab19004d2e53eae8160ab1.sys

Detects loading of driver 1fc7aeeff3ab19004d2e53eae8160ab1.sys via hash. Cisco Talos has identified multiple versions of an undocumented malicious driver named “RedDriver,” a driver-based browser hijacker that uses the Windows Filtering Platform (WFP) to intercept browser traffic. RedDriver has been active since at least 2021. RedDriver utilizes HookSignTool to forge its signature timestamp to bypass Windows driver-signing policies. Code from multiple open-source tools has been used in the devel

loldrivers high sigma

Driver Load - 2.sys

Detects loading of driver 2.sys via hash. Driver categorized as POORTRY by Mandiant.

loldrivers high sigma

Driver Load - 360netmon_wfp.sys

Detects loading of driver 360netmon_wfp.sys via hash. Qihoo 360netmon_wfp.sys is a signed kernel driver documented by ESET as the driver abused by the GentleKiller Network Blocker variant used in Gentlemen ransomware intrusions. The sample is associated with ESET detection Win64/VulnDriver.Qihoo360.A.

loldrivers high sigma

Driver Load - 4118b86e490aed091b1a219dba45f332.sys

Detects loading of driver 4118b86e490aed091b1a219dba45f332.sys via hash. Cisco Talos has identified multiple versions of an undocumented malicious driver named “RedDriver,” a driver-based browser hijacker that uses the Windows Filtering Platform (WFP) to intercept browser traffic. RedDriver has been active since at least 2021. RedDriver utilizes HookSignTool to forge its signature timestamp to bypass Windows driver-signing policies. Code from multiple open-source tools has been used in the devel

loldrivers high sigma

Driver Load - 4748696211bd56c2d93c21cab91e82a5.sys

Detects loading of driver 4748696211bd56c2d93c21cab91e82a5.sys via hash. Cisco Talos has identified multiple versions of an undocumented malicious driver named “RedDriver,” a driver-based browser hijacker that uses the Windows Filtering Platform (WFP) to intercept browser traffic. RedDriver has been active since at least 2021. RedDriver utilizes HookSignTool to forge its signature timestamp to bypass Windows driver-signing policies. Code from multiple open-source tools has been used in the devel

loldrivers high sigma

Driver Load - 4.sys

Detects loading of driver 4.sys via hash. SentinelOne has observed prominent threat actors abusing legitimately signed Microsoft drivers in active intrusions into telecommunication, BPO, MSSP, and financial services businesses. Investigations into these intrusions led to the discovery of POORTRY and STONESTOP malware, part of a small toolkit designed to terminate AV and EDR processes. We first reported our discovery to Microsoft’s Security Response Center (MSRC) in October 2022 and received an o

loldrivers high sigma

Driver Load - 5a4fe297c7d42539303137b6d75b150d.sys

Detects loading of driver 5a4fe297c7d42539303137b6d75b150d.sys via hash. Cisco Talos has identified multiple versions of an undocumented malicious driver named “RedDriver,” a driver-based browser hijacker that uses the Windows Filtering Platform (WFP) to intercept browser traffic. RedDriver has been active since at least 2021. RedDriver utilizes HookSignTool to forge its signature timestamp to bypass Windows driver-signing policies. Code from multiple open-source tools has been used in the devel

loldrivers high sigma

Driver Load - 6771b13a53b9c7449d4891e427735ea2.sys

Detects loading of driver 6771b13a53b9c7449d4891e427735ea2.sys via hash. Cisco Talos has identified multiple versions of an undocumented malicious driver named “RedDriver,” a driver-based browser hijacker that uses the Windows Filtering Platform (WFP) to intercept browser traffic. RedDriver has been active since at least 2021. RedDriver utilizes HookSignTool to forge its signature timestamp to bypass Windows driver-signing policies. Code from multiple open-source tools has been used in the devel

loldrivers high sigma

Driver Load - 6c8a.sys

Detects loading of driver 6c8a.sys via hash. 6c8a.sys is a vulnerable kernel driver from the KeServiceDescriptorTable/vulnerable-drivers repository. The driver exposes dangerous kernel primitives to usermode.

loldrivers high sigma

Driver Load - 7.sys

Detects loading of driver 7.sys via hash. Driver categorized as POORTRY by Mandiant.

loldrivers high sigma

Driver Load - 834761775.sys

Detects loading of driver 834761775.sys via hash. Cisco Talos has identified multiple versions of an undocumented malicious driver named “RedDriver,” a driver-based browser hijacker that uses the Windows Filtering Platform (WFP) to intercept browser traffic. RedDriver has been active since at least 2021. RedDriver utilizes HookSignTool to forge its signature timestamp to bypass Windows driver-signing policies. Code from multiple open-source tools has been used in the development of RedDriver's i

loldrivers high sigma

Driver Load - 8492937_2_Driver.sys

Detects loading of driver 8492937_2_Driver.sys via hash. ABYSSWORKER is a malicious driver used in MEDUSA ransomware attacks to disable EDR systems. The driver masquerades as a legitimate CrowdStrike Falcon driver and provides extensive capabilities to terminate processes, remove security callbacks, manipulate files, and disable security tools. It uses stolen certificates from Chinese companies and requires a specific password for activation. The driver was observed being deployed alongside HEAR

loldrivers high sigma

Driver Load - 927e3aef03a8355d236230cace376b3023480a40c5ac08453c07dab343dd1f11

Detects loading of driver 927e3aef03a8355d236230cace376b3023480a40c5ac08453c07dab343dd1f11 via hash. According to Sophos X-Ops (Aug 06, 2025), a widely shared EDR-killer toolkit drops/loads a malicious kernel driver signed with compromised or revoked certificates to disable endpoint protections. Variants target many vendors, and are commonly HeartCrypt-packed and used by ransomware groups (e.g., RansomHub, INC). The payload uses hard-coded driver names (e.g., mraml.sys, noedt.sys) and kills secu

loldrivers high sigma

Driver Load - a236e7d654cd932b7d11cb604629a2d0.sys

Detects loading of driver a236e7d654cd932b7d11cb604629a2d0.sys via hash. Cisco Talos has identified multiple versions of an undocumented malicious driver named “RedDriver,” a driver-based browser hijacker that uses the Windows Filtering Platform (WFP) to intercept browser traffic. RedDriver has been active since at least 2021. RedDriver utilizes HookSignTool to forge its signature timestamp to bypass Windows driver-signing policies. Code from multiple open-source tools has been used in the devel

loldrivers high sigma

Driver Load - a26363e7b02b13f2b8d697abb90cd5c3.sys

Detects loading of driver a26363e7b02b13f2b8d697abb90cd5c3.sys via hash. Cisco Talos has identified multiple versions of an undocumented malicious driver named “RedDriver,” a driver-based browser hijacker that uses the Windows Filtering Platform (WFP) to intercept browser traffic. RedDriver has been active since at least 2021. RedDriver utilizes HookSignTool to forge its signature timestamp to bypass Windows driver-signing policies. Code from multiple open-source tools has been used in the devel

loldrivers high sigma

Driver Load - a9df5964635ef8bd567ae487c3d214c4.sys

Detects loading of driver a9df5964635ef8bd567ae487c3d214c4.sys via hash. Cisco Talos has identified multiple versions of an undocumented malicious driver named “RedDriver,” a driver-based browser hijacker that uses the Windows Filtering Platform (WFP) to intercept browser traffic. RedDriver has been active since at least 2021. RedDriver utilizes HookSignTool to forge its signature timestamp to bypass Windows driver-signing policies. Code from multiple open-source tools has been used in the devel

loldrivers high sigma

Driver Load - AccelLid.sys

Detects loading of driver AccelLid.sys via hash. AccelLid.sys is an Elitegroup Computer Systems lid accelerometer kernel driver. Northwave Cyber Security reported a local denial-of-service vulnerability with a CVSSv3 score of 5.5. The driver exposes IOCTL paths for accelerometer commands, keyboard control, event registration, and ACPI method execution. Microsoft's vulnerable driver blocklist denies AccelLid.sys across all file versions for matching Elitegroup publisher and signing roots.

loldrivers high sigma

Driver Load - ACE-BASE.sys

Detects loading of driver ACE-BASE.sys via hash. Allows privilege escalation from regular user to System or PPL

loldrivers high sigma

Driver Load - ACPIx86.sys

Detects loading of driver ACPIx86.sys via hash. ABYSSWORKER is a malicious driver used in MEDUSA ransomware attacks to disable EDR systems. The driver masquerades as a legitimate CrowdStrike Falcon driver and provides extensive capabilities to terminate processes, remove security callbacks, manipulate files, and disable security tools. It uses stolen certificates from Chinese companies and requires a specific password for activation. The driver was observed being deployed alongside HEARTCRYPT-pa