Windows: Sysmon filter driver unloaded using fltMC.exe
Identifies fltMC.exe commands attempting to unload the Sysmon filter driver via “unload sysmon”.
- Product
- windows
- Category
- process_creation
- Author
- Kirill Kiryanov, oscd.community (SigmaHQ), DRL 1.1
- Published
- 2019-10-23
- Updated
- 2026-07-31
ATT&CK techniques
Defense EvasionRecon
Resource Dev
Initial Access
Execution
Persistence
Priv Esc
Defense Evasion
Cred Access
Discovery
Lateral Movement
Collection
C2
Exfiltration
Impact
What it detects
This rule flags process executions where fltMC.exe is used with command-line arguments that include both 'unload' and 'sysmon', indicating an attempt to unload the Sysmon filter driver. Attackers may use driver unloading to reduce visibility or impair defensive monitoring. It relies on Windows process creation telemetry, matching the process image/original filename and the contents of the command line.
Reporting behind it
Changelog
v2- v2Candidate ingested via manual entry.2026-07-31
- v1No changelog recorded for this version.2026-07-30
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.
title: "Windows: Sysmon filter driver unloaded using fltMC.exe"
id: 1567156c-ed87-4e84-9873-7e2df3e6bece
related:
- id: 4931188c-178e-4ee7-a348-39e8a7a56821
type: similar
- id: 4d7cda18-1b12-4e52-b45c-d28653210df8
type: derived
status: test
description: This rule flags process executions where fltMC.exe is used with command-line arguments that include both 'unload' and 'sysmon', indicating an attempt to unload the Sysmon filter driver. Attackers may use driver unloading to reduce visibility or impair defensive monitoring. It relies on Windows process creation telemetry, matching the process image/original filename and the contents of the command line.
references:
- https://www.darkoperator.com/blog/2018/10/5/operating-offensively-against-sysmon
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_fltmc_unload_driver_sysmon.yml
author: Kirill Kiryanov, oscd.community, Huntrule Team
date: 2019-10-23
modified: 2023-02-13
tags:
- attack.stealth
- attack.defense-impairment
- attack.t1070
- attack.t1685
- attack.t1685.001
logsource:
product: windows
category: process_creation
detection:
selection_img:
- Image|endswith: \fltMC.exe
- OriginalFileName: fltMC.exe
selection_cli:
CommandLine|contains|all:
- unload
- sysmon
condition: all of selection_*
falsepositives:
- Unlikely
level: high
license: DRL-1.1