Filter Driver Unloaded Via Fltmc.EXE

Rule Info

Name
Filter Driver Unloaded Via Fltmc.EXE
Author
Nasreddine Bencherchali (Nextron Systems)
Description
Detect filter driver unloading activity via fltmc.exe
Date
2023-02-13 00:00:00
Modified
2024-06-24 00:00:00
Id
4931188c-178e-4ee7-a348-39e8a7a56821
Tags
attack.defense-evasion attack.t1070 attack.t1562 attack.t1562.002
Type
Community Rule

Rule History

Author
Title
Date
Commit
Nasreddine Bencherchali
Merge PR #4950 from @nasbench - Comply With v2 Spec Changes
2024-08-12
Nasreddine Bencherchali
Update Rules (#4872)
2024-06-25
Nasreddine Bencherchali
fix: fp found in testing
2023-03-14
Nasreddine Bencherchali
fix: apply suggestions from code review
2023-02-14
Nasreddine Bencherchali
feat: updates and enhancements
2023-02-14