LOLDrivers high experimental sigma
Driver Load - 6c8a.sys
Detects loading of driver 6c8a.sys via hash. 6c8a.sys is a vulnerable kernel driver from the KeServiceDescriptorTable/vulnerable-drivers repository. The driver exposes dangerous kernel primitives to usermode.
Detection Logic
{
"selection_hashes": {
"Hashes
| contains": [
"MD5=7039952d33cbef5d5b818a42d83b3cd2",
"SHA1=9f390c92c2a268e05a0eceb195f396499ff4514a",
"SHA256=8fc5300027547e0eb446239c2a2b95016a9cd25816576407c64389ad12676c8a",
"IMPHASH=a8633e68c2ad9f3dc83775d8d5b21c5b"
]
},
"condition": "selection_hashes"
} False Positives
- ⚠ Unknown
Field Validations
Loading…
Comments (0)
Loading comments...