Browse Rules

Search and filter across all detection sources

1,195 rules

loldrivers low sigma

Driver Load - 1109.sys

Detects loading of driver 1109.sys via name. 1109.sys is a vulnerable kernel driver from the KeServiceDescriptorTable/vulnerable-drivers repository. The driver exposes dangerous kernel primitives to usermode.

loldrivers high sigma

Driver Load - 1109.sys

Detects loading of driver 1109.sys via hash. 1109.sys is a vulnerable kernel driver from the KeServiceDescriptorTable/vulnerable-drivers repository. The driver exposes dangerous kernel primitives to usermode.

loldrivers medium sigma

Driver Load - 1fc7aeeff3ab19004d2e53eae8160ab1.sys

Detects loading of driver 1fc7aeeff3ab19004d2e53eae8160ab1.sys via name. Cisco Talos has identified multiple versions of an undocumented malicious driver named “RedDriver,” a driver-based browser hijacker that uses the Windows Filtering Platform (WFP) to intercept browser traffic. RedDriver has been active since at least 2021. RedDriver utilizes HookSignTool to forge its signature timestamp to bypass Windows driver-signing policies. Code from multiple open-source tools has been used in the devel

loldrivers high sigma

Driver Load - 1fc7aeeff3ab19004d2e53eae8160ab1.sys

Detects loading of driver 1fc7aeeff3ab19004d2e53eae8160ab1.sys via hash. Cisco Talos has identified multiple versions of an undocumented malicious driver named “RedDriver,” a driver-based browser hijacker that uses the Windows Filtering Platform (WFP) to intercept browser traffic. RedDriver has been active since at least 2021. RedDriver utilizes HookSignTool to forge its signature timestamp to bypass Windows driver-signing policies. Code from multiple open-source tools has been used in the devel

loldrivers low sigma

Driver Load - 1.sys

Detects loading of driver 1.sys via name.

loldrivers medium sigma

Driver Load - 2.sys

Detects loading of driver 2.sys via name. Driver categorized as POORTRY by Mandiant.

loldrivers high sigma

Driver Load - 2.sys

Detects loading of driver 2.sys via hash. Driver categorized as POORTRY by Mandiant.

loldrivers low sigma

Driver Load - 360netmon_wfp.sys

Detects loading of driver 360netmon_wfp.sys via name. Qihoo 360netmon_wfp.sys is a signed kernel driver documented by ESET as the driver abused by the GentleKiller Network Blocker variant used in Gentlemen ransomware intrusions. The sample is associated with ESET detection Win64/VulnDriver.Qihoo360.A.

loldrivers high sigma

Driver Load - 360netmon_wfp.sys

Detects loading of driver 360netmon_wfp.sys via hash. Qihoo 360netmon_wfp.sys is a signed kernel driver documented by ESET as the driver abused by the GentleKiller Network Blocker variant used in Gentlemen ransomware intrusions. The sample is associated with ESET detection Win64/VulnDriver.Qihoo360.A.

loldrivers medium sigma

Driver Load - 4118b86e490aed091b1a219dba45f332.sys

Detects loading of driver 4118b86e490aed091b1a219dba45f332.sys via name. Cisco Talos has identified multiple versions of an undocumented malicious driver named “RedDriver,” a driver-based browser hijacker that uses the Windows Filtering Platform (WFP) to intercept browser traffic. RedDriver has been active since at least 2021. RedDriver utilizes HookSignTool to forge its signature timestamp to bypass Windows driver-signing policies. Code from multiple open-source tools has been used in the devel

loldrivers high sigma

Driver Load - 4118b86e490aed091b1a219dba45f332.sys

Detects loading of driver 4118b86e490aed091b1a219dba45f332.sys via hash. Cisco Talos has identified multiple versions of an undocumented malicious driver named “RedDriver,” a driver-based browser hijacker that uses the Windows Filtering Platform (WFP) to intercept browser traffic. RedDriver has been active since at least 2021. RedDriver utilizes HookSignTool to forge its signature timestamp to bypass Windows driver-signing policies. Code from multiple open-source tools has been used in the devel

loldrivers medium sigma

Driver Load - 4748696211bd56c2d93c21cab91e82a5.sys

Detects loading of driver 4748696211bd56c2d93c21cab91e82a5.sys via name. Cisco Talos has identified multiple versions of an undocumented malicious driver named “RedDriver,” a driver-based browser hijacker that uses the Windows Filtering Platform (WFP) to intercept browser traffic. RedDriver has been active since at least 2021. RedDriver utilizes HookSignTool to forge its signature timestamp to bypass Windows driver-signing policies. Code from multiple open-source tools has been used in the devel

loldrivers high sigma

Driver Load - 4748696211bd56c2d93c21cab91e82a5.sys

Detects loading of driver 4748696211bd56c2d93c21cab91e82a5.sys via hash. Cisco Talos has identified multiple versions of an undocumented malicious driver named “RedDriver,” a driver-based browser hijacker that uses the Windows Filtering Platform (WFP) to intercept browser traffic. RedDriver has been active since at least 2021. RedDriver utilizes HookSignTool to forge its signature timestamp to bypass Windows driver-signing policies. Code from multiple open-source tools has been used in the devel

loldrivers medium sigma

Driver Load - 4.sys

Detects loading of driver 4.sys via name. SentinelOne has observed prominent threat actors abusing legitimately signed Microsoft drivers in active intrusions into telecommunication, BPO, MSSP, and financial services businesses. Investigations into these intrusions led to the discovery of POORTRY and STONESTOP malware, part of a small toolkit designed to terminate AV and EDR processes. We first reported our discovery to Microsoft’s Security Response Center (MSRC) in October 2022 and received an o

loldrivers high sigma

Driver Load - 4.sys

Detects loading of driver 4.sys via hash. SentinelOne has observed prominent threat actors abusing legitimately signed Microsoft drivers in active intrusions into telecommunication, BPO, MSSP, and financial services businesses. Investigations into these intrusions led to the discovery of POORTRY and STONESTOP malware, part of a small toolkit designed to terminate AV and EDR processes. We first reported our discovery to Microsoft’s Security Response Center (MSRC) in October 2022 and received an o

loldrivers medium sigma

Driver Load - 5a4fe297c7d42539303137b6d75b150d.sys

Detects loading of driver 5a4fe297c7d42539303137b6d75b150d.sys via name. Cisco Talos has identified multiple versions of an undocumented malicious driver named “RedDriver,” a driver-based browser hijacker that uses the Windows Filtering Platform (WFP) to intercept browser traffic. RedDriver has been active since at least 2021. RedDriver utilizes HookSignTool to forge its signature timestamp to bypass Windows driver-signing policies. Code from multiple open-source tools has been used in the devel

loldrivers high sigma

Driver Load - 5a4fe297c7d42539303137b6d75b150d.sys

Detects loading of driver 5a4fe297c7d42539303137b6d75b150d.sys via hash. Cisco Talos has identified multiple versions of an undocumented malicious driver named “RedDriver,” a driver-based browser hijacker that uses the Windows Filtering Platform (WFP) to intercept browser traffic. RedDriver has been active since at least 2021. RedDriver utilizes HookSignTool to forge its signature timestamp to bypass Windows driver-signing policies. Code from multiple open-source tools has been used in the devel

loldrivers medium sigma

Driver Load - 6771b13a53b9c7449d4891e427735ea2.sys

Detects loading of driver 6771b13a53b9c7449d4891e427735ea2.sys via name. Cisco Talos has identified multiple versions of an undocumented malicious driver named “RedDriver,” a driver-based browser hijacker that uses the Windows Filtering Platform (WFP) to intercept browser traffic. RedDriver has been active since at least 2021. RedDriver utilizes HookSignTool to forge its signature timestamp to bypass Windows driver-signing policies. Code from multiple open-source tools has been used in the devel

loldrivers high sigma

Driver Load - 6771b13a53b9c7449d4891e427735ea2.sys

Detects loading of driver 6771b13a53b9c7449d4891e427735ea2.sys via hash. Cisco Talos has identified multiple versions of an undocumented malicious driver named “RedDriver,” a driver-based browser hijacker that uses the Windows Filtering Platform (WFP) to intercept browser traffic. RedDriver has been active since at least 2021. RedDriver utilizes HookSignTool to forge its signature timestamp to bypass Windows driver-signing policies. Code from multiple open-source tools has been used in the devel

loldrivers low sigma

Driver Load - 6c8a.sys

Detects loading of driver 6c8a.sys via name. 6c8a.sys is a vulnerable kernel driver from the KeServiceDescriptorTable/vulnerable-drivers repository. The driver exposes dangerous kernel primitives to usermode.

loldrivers high sigma

Driver Load - 6c8a.sys

Detects loading of driver 6c8a.sys via hash. 6c8a.sys is a vulnerable kernel driver from the KeServiceDescriptorTable/vulnerable-drivers repository. The driver exposes dangerous kernel primitives to usermode.

loldrivers medium sigma

Driver Load - 7.sys

Detects loading of driver 7.sys via name. Driver categorized as POORTRY by Mandiant.

loldrivers high sigma

Driver Load - 7.sys

Detects loading of driver 7.sys via hash. Driver categorized as POORTRY by Mandiant.

loldrivers low sigma

Driver Load - 80.sys

Detects loading of driver 80.sys via name.

loldrivers low sigma

Driver Load - 81.sys

Detects loading of driver 81.sys via name.