LOLDrivers high experimental sigma
Driver Load - pskmad_64.sys
Detects loading of driver pskmad_64.sys via hash. Panda Kernel Memory Access Driver versions through 1.1.0.21 are affected by CVE-2023-6330, CVE-2023-6331, and CVE-2023-6332. This signed 1.0.0.17 build exposes the \\Device\\PSMEMDriver interface and handles IOCTL 0xB3702C08, which can trigger an out-of-bounds write or disclose arbitrary kernel memory because request data and memory ranges are not adequately validated. The flaws can cause a system crash, leak sensitive kernel data, and may support kernel code execution when chained with another weakness.
Detection Logic
{
"selection_hashes": {
"Hashes
| contains": [
"MD5=9746d407113028f9cdac7031d717203e",
"SHA1=c582269f43c2d4e1894ff53116bccb9f4abc5acc",
"SHA256=7f9a397038732678c52a73e5e2238ab3619e3c1fcb2ce41efc8e5bd38d77f83e",
"IMPHASH=4cc218740b780c7d3e40804b184c2b5d"
]
},
"condition": "selection_hashes"
} False Positives
- ⚠ Unknown
Field Validations
Loading…
Comments (0)
Loading comments...