Vulnerable Driver Load Detection (BYOVD) - Defender

This rule detects the loading of known vulnerable drivers on Windows systems by cross-referencing driver load events with a curated list of vulnerable drivers maintained by LOLDrivers.io. This technique, commonly referred to as 'Bring Your Own Vulnerable Driver' (BYOVD), is frequently used by adversaries to escalate privileges or perform kernel-mode exploitation.