Malicious Qilin EDR Killer BYOVD Driver Load

PremiumReviewedSigma · High · v1
Product
windows
Category
driver_load
Author
HuntRule
Published
2026-09-09
Updated
2026-09-09

ATT&CK techniques

Priv Esc
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Defense Evasion

  7. Cred Access

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule detects loading of the vulnerable drivers rwdrv.sys or hlpdrv.sys used by the Qilin EDR killer as a bring-your-own-vulnerable-driver toolkit. The rwdrv.sys component is a renamed ThrottleStop driver abused alongside hlpdrv.sys to gain kernel access for terminating protected security processes. Loading either driver indicates an attempt to disable endpoint defenses ahead of ransomware deployment.

Related detections9 linkedT1685 — drag to rearrange
Malicious Known Vulnerable Driver Load for BYOVD Attack
Suspicious Masqueraded Zemana Driver Written to Disk via updatedrv (via file_event)
Malicious Vulnerable Driver Load for BYOVD Defense Evasion (via image_load)
Suspicious Vulnerable ASUS AsIO3.sys Driver Load
Malicious Windows Defender Exclusion Added (via registry_set)
Suspicious Termination of Windows Security Health UI via taskkill
Malicious Forced Deletion of Security Vendor Kernel Drivers by ValleyRAT
Suspicious Defender Exclusion Added via Add-MpPreference by GachiLoader
Suspicious TCC AppleEvents Reset via tccutil
Malicious Qilin EDR Killer BYOVD Driver Load
Pivot detection · T1685 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.