LOLDrivers low experimental sigma
Driver Load - 360netmon_wfp.sys
Detects loading of driver 360netmon_wfp.sys via name. Qihoo 360netmon_wfp.sys is a signed kernel driver documented by ESET as the driver abused by the GentleKiller Network Blocker variant used in Gentlemen ransomware intrusions. The sample is associated with ESET detection Win64/VulnDriver.Qihoo360.A.
Detection Logic
{
"selection_name": {
"ImageLoaded
| endswith": [
"\\360netmon_wfp.sys"
]
},
"condition": "selection_name"
} False Positives
- ⚠ Unknown
Field Validations
Loading…
Comments (0)
Loading comments...