Storm-2603 BYOVD - NSecKrnl.sys Written or Loaded

This rule detects the creation and loading of the 'NSecKrnl.sys' driver file on a system. The filename is associated with potentially malicious or unauthorized kernel-level activity, often indicative of rootkit behavior or unauthorized persistence mechanisms.