BYOVD Suspicious Driver Load Outside System32 Drivers Directory

Detects the loading of system drivers (.sys files) that are either unsigned or have an invalid digital signature. The rule excludes drivers loaded from common Windows system directories to minimize noise. This behavior is a common indicator of rootkit installation or the use of vulnerable drivers for kernel-mode exploitation.