BYOVD: TrueSight/rentdrv2 Driver Load with Process-Kill IOCTL
This rule monitors for the loading or interaction with specific device drivers named 'truesight.sys' or 'rentdrv2.sys'. These drivers are often associated with malicious activity, including potentially vulnerable kernel drivers used in BYOVD (Bring Your Own Vulnerable Driver) attacks or rootkit-like persistence mechanisms. The rule tracks driver loading, registry updates, process activity, and device I/O control calls related to these files.
CQL

