Vulnerable Driver Load Detection (BYOVD) - Sysmon
Detects the loading of known vulnerable drivers (BYOVD - Bring Your Own Vulnerable Driver) by cross-referencing Sysmon Event ID 6 (Driver Loaded) image hashes with the LOLDrivers.io project database. This technique is often used by adversaries to elevate privileges to kernel mode by exploiting vulnerabilities within signed, legitimate drivers.
Microsoft Sentinel (KQL)

