
Rule Info
Name
Filter Driver Unloaded Via Fltmc.EXE
Author
Nasreddine Bencherchali (Nextron Systems)
Description
Detect filter driver unloading activity via fltmc.exe
Date
2023-02-13 00:00:00
Modified
2024-06-24 00:00:00
Id
4931188c-178e-4ee7-a348-39e8a7a56821
Tags
attack.defense-evasion attack.t1070 attack.t1562 attack.t1562.002
Type
Community Rule
Link to Public Repo
Rule History
Author
Title
Date
Commit
Nasreddine Bencherchali
Merge PR #4950 from @nasbench - Comply With v2 Spec Changes
2024-08-12