Browse Rules

Search and filter across all detection sources

4,276 rules

elastic low eql

Launch Service Creation and Immediate Loading

An adversary can establish persistence by installing a new launch agent that executes at login by using launchd or launchctl to load a plist into the appropriate directories.

elastic low eql

Potential Application Shimming via Sdbinst

The Application Shim was created to allow for backward compatibility of software as the operating system codebase changes over time. This Windows functionality has been abused by attackers to stealthily gain persistence and arbitrary code execution in legitimate Windows processes.

loldrivers low sigma

Driver Load - 1109.sys

Detects loading of driver 1109.sys via name. 1109.sys is a vulnerable kernel driver from the KeServiceDescriptorTable/vulnerable-drivers repository. The driver exposes dangerous kernel primitives to usermode.

loldrivers low sigma

Driver Load - 1.sys

Detects loading of driver 1.sys via name.

loldrivers low sigma

Driver Load - 360netmon_wfp.sys

Detects loading of driver 360netmon_wfp.sys via name. Qihoo 360netmon_wfp.sys is a signed kernel driver documented by ESET as the driver abused by the GentleKiller Network Blocker variant used in Gentlemen ransomware intrusions. The sample is associated with ESET detection Win64/VulnDriver.Qihoo360.A.

loldrivers low sigma

Driver Load - 6c8a.sys

Detects loading of driver 6c8a.sys via name. 6c8a.sys is a vulnerable kernel driver from the KeServiceDescriptorTable/vulnerable-drivers repository. The driver exposes dangerous kernel primitives to usermode.

loldrivers low sigma

Driver Load - 80.sys

Detects loading of driver 80.sys via name.

loldrivers low sigma

Driver Load - 81.sys

Detects loading of driver 81.sys via name.

loldrivers low sigma

Driver Load - 8492937_2_Driver.sys

Detects loading of driver 8492937_2_Driver.sys via name. ABYSSWORKER is a malicious driver used in MEDUSA ransomware attacks to disable EDR systems. The driver masquerades as a legitimate CrowdStrike Falcon driver and provides extensive capabilities to terminate processes, remove security callbacks, manipulate files, and disable security tools. It uses stolen certificates from Chinese companies and requires a specific password for activation. The driver was observed being deployed alongside HEAR

loldrivers low sigma

Driver Load - 927e3aef03a8355d236230cace376b3023480a40c5ac08453c07dab343dd1f11

Detects loading of driver 927e3aef03a8355d236230cace376b3023480a40c5ac08453c07dab343dd1f11 via name. According to Sophos X-Ops (Aug 06, 2025), a widely shared EDR-killer toolkit drops/loads a malicious kernel driver signed with compromised or revoked certificates to disable endpoint protections. Variants target many vendors, and are commonly HeartCrypt-packed and used by ransomware groups (e.g., RansomHub, INC). The payload uses hard-coded driver names (e.g., mraml.sys, noedt.sys) and kills secu

loldrivers low sigma

Driver Load - AccelLid.sys

Detects loading of driver AccelLid.sys via name. AccelLid.sys is an Elitegroup Computer Systems lid accelerometer kernel driver. Northwave Cyber Security reported a local denial-of-service vulnerability with a CVSSv3 score of 5.5. The driver exposes IOCTL paths for accelerometer commands, keyboard control, event registration, and ACPI method execution. Microsoft's vulnerable driver blocklist denies AccelLid.sys across all file versions for matching Elitegroup publisher and signing roots.

loldrivers low sigma

Driver Load - ACE-BASE.sys

Detects loading of driver ACE-BASE.sys via name. Allows privilege escalation from regular user to System or PPL

loldrivers low sigma

Driver Load - ACPIx86.sys

Detects loading of driver ACPIx86.sys via name. ABYSSWORKER is a malicious driver used in MEDUSA ransomware attacks to disable EDR systems. The driver masquerades as a legitimate CrowdStrike Falcon driver and provides extensive capabilities to terminate processes, remove security callbacks, manipulate files, and disable security tools. It uses stolen certificates from Chinese companies and requires a specific password for activation. The driver was observed being deployed alongside HEARTCRYPT-pa

loldrivers low sigma

Driver Load - ADRMDRVSYS.sys

Detects loading of driver ADRMDRVSYS.sys via name. ADLINK Resource Manager exposes physical-memory mapping through IOCTL 0x2234D4, allowing low-privilege callers to read kernel memory. The interface has also been weaponized by Blackout Reloaded to terminate protected antimalware processes through a driver path that reaches ZwTerminateProcess.

loldrivers low sigma

Driver Load - ADV64DRV.sys

Detects loading of driver ADV64DRV.sys via name.

loldrivers low sigma

Driver Load - AdvCare.sys

Detects loading of driver AdvCare.sys via name. AdvCare.sys is a legacy hardware health monitor driver from Advantech Co., Ltd. for industrial PCs and embedded boards. The driver exposes arbitrary MSR read/write (wrmsr/rdmsr with no validation), arbitrary physical memory read/write via MmMapIoSpace, unrestricted port I/O across all 65536 ports, and PCI configuration space read/write via HalGetBusDataByOffset/HalSetBusDataByOffset. The device is created with IoCreateDevice (no DACL) and IRP_MJ_CR

loldrivers low sigma

Driver Load - Afd.sys

Detects loading of driver Afd.sys via name. Windows Ancillary Function Driver (Afd.sys) for WinSock is vulnerable to an Elevation of Privilege Vulnerability.

loldrivers low sigma

Driver Load - Agent64.sys

Detects loading of driver Agent64.sys via name. DriverAgent Direct I/O for 64-bit Windows

loldrivers low sigma

Driver Load - AIDA64Driver.sys

Detects loading of driver AIDA64Driver.sys via name. AIDA64Driver.sys is a vulnerable kernel driver from the KeServiceDescriptorTable/vulnerable-drivers repository. The driver exposes dangerous kernel primitives to usermode.

loldrivers low sigma

Driver Load - ALSysIO64.sys

Detects loading of driver ALSysIO64.sys via name. ALSysIO64

loldrivers low sigma

Driver Load - AMDPowerProfiler.sys

Detects loading of driver AMDPowerProfiler.sys via name. AMD uProf AMDPowerProfiler.sys is affected by CVE-2021-26334. Insufficient access control permits lower-privileged callers to access model-specific registers, which can lead to privilege escalation and ring-0 code execution. AMD addresses the issue in the Windows uProf 3.4.494 release.

loldrivers low sigma

Driver Load - Amd_RPMC_BiosToolCommonDriver.sys

Detects loading of driver Amd_RPMC_BiosToolCommonDriver.sys via name. Amd_RPMC_BiosToolCommonDriver.sys is a vulnerable kernel driver from the KeServiceDescriptorTable/vulnerable-drivers repository. The driver exposes dangerous kernel primitives to usermode.

loldrivers low sigma

Driver Load - AMDRyzenMasterDriver.sys

Detects loading of driver AMDRyzenMasterDriver.sys via name. AMD Ryzen Master drivers affected by CVE-2023-20564 insufficiently validate IOCTL input buffers. A privileged caller can read or write memory through the exposed interface, potentially enabling arbitrary kernel execution.

loldrivers low sigma

Driver Load - amifldrv64.sys

Detects loading of driver amifldrv64.sys via name. AMI Generic Utility Driver

loldrivers low sigma

Driver Load - amigendrv64.sys

Detects loading of driver amigendrv64.sys via name.