Kernel Driver Mass Termination of PPL-Protected Security Processes
This rule detects the potential bypassing of Protected Process Light (PPL) in Windows, characterized by kernel-mode driver activity (such as ObOpenObjectByPointer) correlated with the mass termination of security-related processes (e.g., Defender, CrowdStrike, SentinelOne). The correlation between driver-level object handle manipulation and the termination of protected security binaries is a strong indicator of an adversary attempting to disable EDR/AV protections via kernel exploitation or driver abuse.
Splunk (SPL)

