DragonForce BYOVD Kernel Driver Load: TrueSight or rentdrv2
This rule monitors process execution and registry modifications for filenames, process command lines, or registry keys associated with 'truesight.sys' and 'rentdrv2.sys'. These artifacts are typically associated with malicious kernel-mode drivers, such as rootkits, often used for stealth or persistence on Windows systems.
Cortex XDR

