Suspicious Dell DBUtilDrv2 Vulnerable Driver Load via driver_load

PremiumReviewedSigma · High · v1
Product
windows
Category
driver_load
Author
HuntRule
Published
2026-10-06
Updated
2026-10-06

ATT&CK techniques

Priv Esc
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Defense Evasion

  7. Cred Access

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule detects loading of the Dell DBUtilDrv2.sys driver which is a known vulnerable driver abused in bring your own vulnerable driver attacks. ToddyCat installed DBUtilDrv2.sys through a crafted INF to disable kernel notification routines and blind security products. The presence of this signed but vulnerable driver on non Dell maintenance systems is a strong indicator of kernel level tampering.

Related detections9 linkedT1685 — drag to rearrange
Malicious Vulnerable Driver Load via TfSysMon.sys BYOVD (via driver_load)
Malicious Vulnerable Driver Load by GentleKiller BYOVD EDR Killer
Malicious Known Vulnerable Driver Load for BYOVD Attack
Malicious Qilin EDR Killer BYOVD Driver Load
Suspicious Masqueraded Zemana Driver Written to Disk via updatedrv (via file_event)
Malicious Vulnerable Driver Load for BYOVD Defense Evasion (via image_load)
Suspicious Service ACL Hardening via sc.exe sdset (via process_creation)
Malicious Snatch Ransomware SuperBackupMan SafeBoot Service Registration
Malicious Microsoft Defender Tampering via Registry Values
Suspicious Dell DBUtilDrv2 Vulnerable Driver Load via driver_load
Pivot detection · T1685 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.