BYOVD process termination via TrueSight/rentdrv2 vulnerable drivers
Detects the use of vulnerable kernel drivers, specifically TrueSight.sys and rentdrv2.sys, as part of a Bring Your Own Vulnerable Driver (BYOVD) technique. This activity, associated with DragonForce ransomware, involves registering or accessing these drivers and sending specific IOCTL codes (0x22E044 or 0x22E010) to terminate security software processes.
YARA-L

