Browse Rules

Search and filter across all detection sources

10,637 rules

elastic medium kql

AWS Root Console Login Password Spraying

Identifies failed authentication attempts against the AWS Management Console root user from the same source IP address targeting multiple AWS accounts. Password spraying uses few attempts per target across many accounts to avoid lockout, making per-account volume an unreliable signal. This rule detects the cross-account breadth pattern: a single source IP generating root ConsoleLogin failures across two or more distinct AWS accounts. Requires an AWS Organizations-level CloudTrail trail aggregati

elastic medium eql

Installation of Custom Shim Databases

Identifies the installation of custom Application Compatibility Shim databases. This Windows functionality has been abused by attackers to stealthily gain persistence and arbitrary code execution in legitimate Windows processes.

loldrivers medium sigma

Driver Load - 1fc7aeeff3ab19004d2e53eae8160ab1.sys

Detects loading of driver 1fc7aeeff3ab19004d2e53eae8160ab1.sys via name. Cisco Talos has identified multiple versions of an undocumented malicious driver named “RedDriver,” a driver-based browser hijacker that uses the Windows Filtering Platform (WFP) to intercept browser traffic. RedDriver has been active since at least 2021. RedDriver utilizes HookSignTool to forge its signature timestamp to bypass Windows driver-signing policies. Code from multiple open-source tools has been used in the devel

loldrivers medium sigma

Driver Load - 2.sys

Detects loading of driver 2.sys via name. Driver categorized as POORTRY by Mandiant.

loldrivers medium sigma

Driver Load - 4118b86e490aed091b1a219dba45f332.sys

Detects loading of driver 4118b86e490aed091b1a219dba45f332.sys via name. Cisco Talos has identified multiple versions of an undocumented malicious driver named “RedDriver,” a driver-based browser hijacker that uses the Windows Filtering Platform (WFP) to intercept browser traffic. RedDriver has been active since at least 2021. RedDriver utilizes HookSignTool to forge its signature timestamp to bypass Windows driver-signing policies. Code from multiple open-source tools has been used in the devel

loldrivers medium sigma

Driver Load - 4748696211bd56c2d93c21cab91e82a5.sys

Detects loading of driver 4748696211bd56c2d93c21cab91e82a5.sys via name. Cisco Talos has identified multiple versions of an undocumented malicious driver named “RedDriver,” a driver-based browser hijacker that uses the Windows Filtering Platform (WFP) to intercept browser traffic. RedDriver has been active since at least 2021. RedDriver utilizes HookSignTool to forge its signature timestamp to bypass Windows driver-signing policies. Code from multiple open-source tools has been used in the devel

loldrivers medium sigma

Driver Load - 4.sys

Detects loading of driver 4.sys via name. SentinelOne has observed prominent threat actors abusing legitimately signed Microsoft drivers in active intrusions into telecommunication, BPO, MSSP, and financial services businesses. Investigations into these intrusions led to the discovery of POORTRY and STONESTOP malware, part of a small toolkit designed to terminate AV and EDR processes. We first reported our discovery to Microsoft’s Security Response Center (MSRC) in October 2022 and received an o

loldrivers medium sigma

Driver Load - 5a4fe297c7d42539303137b6d75b150d.sys

Detects loading of driver 5a4fe297c7d42539303137b6d75b150d.sys via name. Cisco Talos has identified multiple versions of an undocumented malicious driver named “RedDriver,” a driver-based browser hijacker that uses the Windows Filtering Platform (WFP) to intercept browser traffic. RedDriver has been active since at least 2021. RedDriver utilizes HookSignTool to forge its signature timestamp to bypass Windows driver-signing policies. Code from multiple open-source tools has been used in the devel

loldrivers medium sigma

Driver Load - 6771b13a53b9c7449d4891e427735ea2.sys

Detects loading of driver 6771b13a53b9c7449d4891e427735ea2.sys via name. Cisco Talos has identified multiple versions of an undocumented malicious driver named “RedDriver,” a driver-based browser hijacker that uses the Windows Filtering Platform (WFP) to intercept browser traffic. RedDriver has been active since at least 2021. RedDriver utilizes HookSignTool to forge its signature timestamp to bypass Windows driver-signing policies. Code from multiple open-source tools has been used in the devel

loldrivers medium sigma

Driver Load - 7.sys

Detects loading of driver 7.sys via name. Driver categorized as POORTRY by Mandiant.

loldrivers medium sigma

Driver Load - 834761775.sys

Detects loading of driver 834761775.sys via name. Cisco Talos has identified multiple versions of an undocumented malicious driver named “RedDriver,” a driver-based browser hijacker that uses the Windows Filtering Platform (WFP) to intercept browser traffic. RedDriver has been active since at least 2021. RedDriver utilizes HookSignTool to forge its signature timestamp to bypass Windows driver-signing policies. Code from multiple open-source tools has been used in the development of RedDriver's i

loldrivers medium sigma

Driver Load - a236e7d654cd932b7d11cb604629a2d0.sys

Detects loading of driver a236e7d654cd932b7d11cb604629a2d0.sys via name. Cisco Talos has identified multiple versions of an undocumented malicious driver named “RedDriver,” a driver-based browser hijacker that uses the Windows Filtering Platform (WFP) to intercept browser traffic. RedDriver has been active since at least 2021. RedDriver utilizes HookSignTool to forge its signature timestamp to bypass Windows driver-signing policies. Code from multiple open-source tools has been used in the devel

loldrivers medium sigma

Driver Load - a26363e7b02b13f2b8d697abb90cd5c3.sys

Detects loading of driver a26363e7b02b13f2b8d697abb90cd5c3.sys via name. Cisco Talos has identified multiple versions of an undocumented malicious driver named “RedDriver,” a driver-based browser hijacker that uses the Windows Filtering Platform (WFP) to intercept browser traffic. RedDriver has been active since at least 2021. RedDriver utilizes HookSignTool to forge its signature timestamp to bypass Windows driver-signing policies. Code from multiple open-source tools has been used in the devel

loldrivers medium sigma

Driver Load - a9df5964635ef8bd567ae487c3d214c4.sys

Detects loading of driver a9df5964635ef8bd567ae487c3d214c4.sys via name. Cisco Talos has identified multiple versions of an undocumented malicious driver named “RedDriver,” a driver-based browser hijacker that uses the Windows Filtering Platform (WFP) to intercept browser traffic. RedDriver has been active since at least 2021. RedDriver utilizes HookSignTool to forge its signature timestamp to bypass Windows driver-signing policies. Code from multiple open-source tools has been used in the devel

loldrivers medium sigma

Driver Load - Air_SYSTEM10.sys

Detects loading of driver Air_SYSTEM10.sys via name. Driver categorized as POORTRY by Mandiant.

loldrivers medium sigma

Driver Load - avkiller.sys

Detects loading of driver avkiller.sys via name. Sophos, from time to time, has observed a threat actor deploy variants of Poortry on different machines within a single estate during an attack. These variants contain the same payload, but signed with a different certificate than the driver first seen used during the attack.

loldrivers medium sigma

Driver Load - be6318413160e589080df02bb3ca6e6a.sys

Detects loading of driver be6318413160e589080df02bb3ca6e6a.sys via name. Cisco Talos has identified multiple versions of an undocumented malicious driver named “RedDriver,” a driver-based browser hijacker that uses the Windows Filtering Platform (WFP) to intercept browser traffic. RedDriver has been active since at least 2021. RedDriver utilizes HookSignTool to forge its signature timestamp to bypass Windows driver-signing policies. Code from multiple open-source tools has been used in the devel

loldrivers medium sigma

Driver Load - blacklotus_driver.sys

Detects loading of driver blacklotus_driver.sys via name. The first in-the-wild UEFI bootkit bypassing UEFI Secure Boot on fully updated UEFI systems is now a reality. Once the persistence is configured, the BlackLotus bootkit is executed on every system start. The bootkits goal is to deploy a kernel driver and a final user-mode component.

loldrivers medium sigma

Driver Load - burntcigar.sys

Detects loading of driver burntcigar.sys via name. BurntCigar (aka POORTRY) is a malicious kernel-mode rootkit driver used by multiple ransomware groups including Cuba, BlackCat, Medusa, LockBit, and RansomHub. Designed to disable and remove EDR solutions by terminating security processes and deleting critical security software files. VMProtect-packed driver signed with stolen Blueone Technology certificate. Detected by 32.9% of AV engines. Facilitates ransomware deployment by rendering systems

loldrivers medium sigma

Driver Load - c94f405c5929cfcccc8ad00b42c95083.sys

Detects loading of driver c94f405c5929cfcccc8ad00b42c95083.sys via name. Cisco Talos has identified multiple versions of an undocumented malicious driver named “RedDriver,” a driver-based browser hijacker that uses the Windows Filtering Platform (WFP) to intercept browser traffic. RedDriver has been active since at least 2021. RedDriver utilizes HookSignTool to forge its signature timestamp to bypass Windows driver-signing policies. Code from multiple open-source tools has been used in the devel

loldrivers medium sigma

Driver Load - changsha

Detects loading of driver changsha via name. Malicious rootkit masquerading as legitimate CrowdStrike Falcon Sensor driver (CSAgent.sys). Signed with stolen/expired Chinese certificate from 2015. Detected by 61.6% of AV engines as Rootkit.Win64.Agent and Trojan:Win64/AVTamper. Used to establish kernel-level persistence while evading detection by impersonating trusted security software.

loldrivers medium sigma

Driver Load - Cndom6.sys

Detects loading of driver Cndom6.sys via name. Signed malicious drivers reported in Silver Fox activity; rwdriver.sys exposes a rootkit IOCTL primitive, while Cndom6.sys and XiaoH.sys are reported as watchdog/support drivers.

loldrivers medium sigma

Driver Load - CSAgent.sys

Detects loading of driver CSAgent.sys via name. AbyssWorker rootkit masquerading as a CrowdStrike Falcon sensor driver (CSAgent.sys). Signed with a revoked certificate from Shenzhen yundian Technology Co., Ltd. This is a fully malicious driver that blinds security products by stripping handles, terminating processes, and removing notification callbacks. Identified in ESET EDR killers research (March 2026) deployed alongside Medusa ransomware via the HEARTCRYPT packer.

loldrivers medium sigma

Driver Load - daxin_blank1.sys

Detects loading of driver daxin_blank1.sys via name. Driver used in the Daxin malware campaign.

loldrivers medium sigma

Driver Load - daxin_blank2.sys

Detects loading of driver daxin_blank2.sys via name. Driver used in the Daxin malware campaign.