Security process termination following ardrv.sys driver load (BYOVD)
This rule detects the termination of specific security-related processes (e.g., antivirus services) shortly after a specific driver, 'ardrv.sys', is loaded on a Windows system. This sequence is characteristic of a 'Bring Your Own Vulnerable Driver' (BYOVD) attack, where an adversary loads a signed but vulnerable kernel driver to gain elevated privileges, which they then use to disable or terminate security monitoring processes.
Microsoft Sentinel (KQL)

