Malicious Vulnerable Driver Load via TfSysMon.sys BYOVD (via driver_load)

PremiumReviewedSigma · High · v1
Product
windows
Category
driver_load
Author
HuntRule
Published
2026-09-25
Updated
2026-09-25

ATT&CK techniques

Priv Esc
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Defense Evasion

  7. Cred Access

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule detects loading of the TfSysMon.sys vulnerable driver abused by the RansomHub Killer tool to disable security products through bring-your-own-vulnerable-driver as reported by Group-IB. Adversaries load this signed but vulnerable driver to terminate AV and EDR processes from kernel space, making its load a strong defense-evasion indicator.

Related detections9 linkedT1685 — drag to rearrange
Malicious Vulnerable Driver Load by GentleKiller BYOVD EDR Killer
Malicious Known Vulnerable Driver Load for BYOVD Attack
Malicious Qilin EDR Killer BYOVD Driver Load
Suspicious Masqueraded Zemana Driver Written to Disk via updatedrv (via file_event)
Malicious Vulnerable Driver Load for BYOVD Defense Evasion (via image_load)
Suspicious Defendnot Antivirus Disabling Component Dropped in ProgramData (via file_event)
Malicious Removal of Defender Safe Mode Service Registration via Process Creation
Suspicious Windows Defender Weakening via MpPreference (via process_creation)
Malicious Whole-Drive Defender Exclusion via Add-MpPreference (via ps_script)
Malicious Vulnerable Driver Load via TfSysMon.sys BYOVD (via driver_load)
Pivot detection · T1685 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.