Storm-2603 BYOVD - NSecKrnl.sys Written or Loaded
This rule detects the creation and loading of the 'NSecKrnl.sys' driver file on a system. The filename is associated with potentially malicious or unauthorized kernel-level activity, often indicative of rootkit behavior or unauthorized persistence mechanisms.
Microsoft Sentinel (KQL)

