• CommunityEnterprisePlans
  • Intel Exchange
    Intel ExchangeDetections
  • Resources
  • About
  • Leaderboard
Join CommunitySign In
    All Detections

    BYOVD process termination via TrueSight/rentdrv2 vulnerable drivers

    avatar
    GlassDiceBearhttps://www.dicebear.comhttps://creativecommons.org/publicdomain/zero/1.0/„Glass” (https://www.dicebear.com) by „DiceBear”, licensed under „CC0 1.0” (https://creativecommons.org/publicdomain/zero/1.0/)
    Ibrahim Saud@tektrix
    •updated 21 days ago•0•0•1

    Detects the use of vulnerable kernel drivers, specifically TrueSight.sys and rentdrv2.sys, as part of a Bring Your Own Vulnerable Driver (BYOVD) technique. This activity, associated with DragonForce ransomware, involves registering or accessing these drivers and sending specific IOCTL codes (0x22E044 or 0x22E010) to terminate security software processes.

    YARA-L

    Tags

    T1068 - Exploitation for Privilege EscalationT1543.003 - Windows ServiceT1014 - RootkitTA0003 - PersistenceTA0005 - StealthDriver LoadProcess TamperingProcess TerminationFile CreationRegistry Value SetWindowsWindows SysmonWindows Eventlog System

    Found in

    • Analysis of DragonForce Windows Ransomware LockerLast updated Sep 9, 2026
    • Analysis of DragonForce Windows Ransomware LockerLast updated Sep 9, 2026
    • Analysis of DragonForce Windows Ransomware LockerLast updated Sep 9, 2026
    • Analysis of DragonForce Windows Ransomware LockerLast updated Sep 9, 2026

    Community Inspired.
    AI Enhanced.
    Better Detections.

    Follow Us

    Company

    • About
    • Leaderboard

    Product

    • Community
    • Enterprise
    • Plans

    © 2026 Copyright. All Rights Reserved.

    Privacy PolicyTerms of Service

    Sign up to view this detection

    or

    Already have an account?