Detects the load of a driver whose SHA256 matches a known-vulnerable (BYOVD) sample from the LOLDrivers corpus, regardless of filename — catches renamed/random-named drops that a filename rule misses. Exact-hash match, near-zero false positive. Forged deterministically. The rule matched on logsource `driver_load`. Verify the event genuinely matches the described behavior, and not a known legitimate case. The rule matches on these fields — examine the exact value in the event:
Investigation queries (read-only):
Relevant defensive analysis techniques (MITRE D3FEND), to apply where the telemetry is available:
Known benign causes for this rule:
The rule's references — CTI context to qualify the incident: