BYOVD Kernel Driver Load - TrueSight/rentdrv2 IOCTL Abuse

Detects the loading of known vulnerable kernel drivers 'truesight.sys' or 'rentdrv2.sys'. These drivers are frequently abused in Bring-Your-Own-Vulnerable-Driver (BYOVD) attack chains, where attackers leverage specific IOCTL calls (such as 0x22E044 or 0x22E010) to interact with the driver to perform privileged actions, such as terminating security processes.