LOLDrivers high experimental sigma
Driver Load - AccelLid.sys
Detects loading of driver AccelLid.sys via hash. AccelLid.sys is an Elitegroup Computer Systems lid accelerometer kernel driver. Northwave Cyber Security reported a local denial-of-service vulnerability with a CVSSv3 score of 5.5. The driver exposes IOCTL paths for accelerometer commands, keyboard control, event registration, and ACPI method execution. Microsoft's vulnerable driver blocklist denies AccelLid.sys across all file versions for matching Elitegroup publisher and signing roots.
Detection Logic
{
"selection_hashes": {
"Hashes
| contains": [
"MD5=833becd0e4abc9cfff8c835694694f80",
"MD5=887e6502a420acb183342c60c396b0e3",
"SHA1=19871a15d483b9be1aa868a31a3384513b05e8ba",
"SHA256=08675796b8712e0e4ccbdf7831450b907bb94c2e3e85560d9aba1b24931f0d55",
"IMPHASH=082b83ad4226208cdab708a369872223"
]
},
"condition": "selection_hashes"
} False Positives
- ⚠ Unknown
Field Validations
Loading…
Comments (0)
Loading comments...