BYOVD - Known Vulnerable Driver Load via File Drop, SCM, or Registry
Detects the deployment, registration, and loading of known vulnerable drivers (e.g., mhyprot2.sys, gdrv.sys, rtcore64.sys) used in Bring Your Own Vulnerable Driver (BYOVD) attacks. This rule monitors file creation, module loading, service registration via sc.exe, and registry modifications associated with service installation.
SentinelOne

