BYOVD Alinubx.sys IOCTL Kernel-Mode AV/EDR Process Kill

Detects evidence of the Alinubx.sys kernel driver being loaded or interacted with via its device interface using a specific IOCTL (0x222024). This driver is known to be abused in Bring Your Own Vulnerable Driver (BYOVD) attacks to terminate security software processes from kernel mode, effectively bypassing Windows Protected Process Light (PPL) protections.