BYOVD Vulnerable Driver Load for EDR Evasion via Service Creation
This rule detects the installation of known vulnerable kernel drivers (Bring Your Own Vulnerable Driver - BYOVD). These drivers are often exploited by adversaries to gain kernel-level code execution, elevate privileges, or disable security tools (EDR).
Microsoft Sentinel (KQL)

