Suspicious Qilin EDR Killer BYOVD Service Installation via sc

PremiumReviewedSigma · High · v1
Product
windows
Category
process_creation
Author
HuntRule
Published
2026-07-28
Updated
2026-08-28

ATT&CK techniques

Persistence → Priv Esc
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Defense Evasion

  6. Cred Access

  7. Discovery

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule detects sc.exe creating a service that references the Qilin EDR killer drivers rwdrv or hlpdrv, matching the installation step that registers the bring-your-own-vulnerable-driver components as kernel services. Registering these drivers as services is how the tool loads them to terminate protected processes and suppress ETW. Service creation for these drivers indicates an imminent attempt to blind endpoint defenses.

Related detections9 linkedT1685 — drag to rearrange
Malicious Bring-Your-Own-Vulnerable-Driver Load for EDR Killing
Windows Defender Tampering via Set-MpPreference and Exclusions
Suspicious Windows Defender Real-Time Protection Disabled via Policy Registry by Cephalus Ransomware
Suspicious RustDesk Remote Access Service Installation via sc (via process_creation)
Suspicious Microsoft Defender Path Exclusion of User Directories (via process_creation)
Malicious Windows Defender Tampering via Set-MpPreference (via process_creation)
Malicious Service Creation Pointing to Public Data File via sc (via process_creation)
Malicious Container Runtime Tampering via chmod on runc (via process_creation)
EAP Service Activation by Liontail Framework for DLL Sideloading - Via Command (via process_creation)
Suspicious Qilin EDR Killer BYOVD Service Installation via sc
Pivot detection · T1685 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.