BYOVD: Unsigned/Suspicious Kernel Driver Drop and Load via sc.exe or fltMC
Detects behaviors associated with 'Bring Your Own Vulnerable Driver' (BYOVD) attacks, including the dropping of .sys driver files into non-canonical directories, the registration and execution of kernel services via sc.exe, the use of fltMC to load filter drivers, and the loading of driver modules from non-standard locations.
SentinelOne

