LOLDrivers medium experimental sigma
Driver Load - avkiller.sys
Detects loading of driver avkiller.sys via name. Sophos, from time to time, has observed a threat actor deploy variants of Poortry on different machines within a single estate during an attack. These variants contain the same payload, but signed with a different certificate than the driver first seen used during the attack.
Detection Logic
{
"selection_name": {
"ImageLoaded
| endswith": [
"\\avkiller.sys"
]
},
"condition": "selection_name"
} False Positives
- ⚠ Unknown
Field Validations
Loading…
Comments (0)
Loading comments...