Suspicious TrueSight Driver Load from Temporary Location
Detects the loading of the 'truesight.sys' driver from non-standard or temporary locations. This activity is associated with a campaign where threat actors use a vulnerable version of this driver to terminate security products before deploying ransomware or RATs, a technique known as Bring Your Own Vulnerable Driver (BYOVD).
Microsoft Sentinel (KQL)

