• CommunityEnterprisePlans
  • Intel Exchange
    Intel ExchangeDetections
  • Resources
  • About
  • Leaderboard
Join CommunitySign In
    All Detections

    DragonForce BYOVD Kernel Driver Load: TrueSight or rentdrv2

    avatar
    GlassDiceBearhttps://www.dicebear.comhttps://creativecommons.org/publicdomain/zero/1.0/„Glass” (https://www.dicebear.com) by „DiceBear”, licensed under „CC0 1.0” (https://creativecommons.org/publicdomain/zero/1.0/)
    Ibrahim Saud@tektrix
    •updated 21 days ago•1•0•5

    This rule monitors process execution and registry modifications for filenames, process command lines, or registry keys associated with 'truesight.sys' and 'rentdrv2.sys'. These artifacts are typically associated with malicious kernel-mode drivers, such as rootkits, often used for stealth or persistence on Windows systems.

    Cortex XDR

    Tags

    T1014 - RootkitT1547.006 - Kernel Modules and ExtensionsT1543.003 - Windows ServiceTA0005 - StealthTA0003 - PersistenceProcess CreationFile EventRegistry EventDriver LoadWindows

    Found in

    • Analysis of DragonForce Windows Ransomware LockerLast updated Sep 9, 2026
    • Analysis of DragonForce Windows Ransomware LockerLast updated Sep 9, 2026
    • Analysis of DragonForce Windows Ransomware LockerLast updated Sep 9, 2026
    • Analysis of DragonForce Windows Ransomware LockerLast updated Sep 9, 2026

    Community Inspired.
    AI Enhanced.
    Better Detections.

    Follow Us

    Company

    • About
    • Leaderboard

    Product

    • Community
    • Enterprise
    • Plans

    © 2026 Copyright. All Rights Reserved.

    Privacy PolicyTerms of Service

    Sign up to view this detection

    or

    Already have an account?