BYOVD Suspicious Driver Load Outside System32 Drivers Directory
Detects the loading of system drivers (.sys files) that are either unsigned or have an invalid digital signature. The rule excludes drivers loaded from common Windows system directories to minimize noise. This behavior is a common indicator of rootkit installation or the use of vulnerable drivers for kernel-mode exploitation.
Splunk (SPL)

