Akira ransomware abuses CPU tuning tool to disable Microsoft Defender
This rule detects the presence of known malicious drivers (hlpdrv.sys, rwdrv.sys) by their SHA256 hash or file path. It also identifies attempts to install these drivers via service creation commands and monitors for modifications to Windows Defender registry keys that could disable its functionality, indicating defense evasion.
Microsoft Sentinel (KQL)

