Best Detection of 2026 Series: BYOVD Vulnerable Driver Load Followed by EDR Process Termination

This rule detects the suspicious loading of known vulnerable drivers (Bring Your Own Vulnerable Driver - BYOVD) via the Windows service control manager (sc.exe) or event log 7045, followed by the immediate termination of major endpoint security software processes within a 300-second window. This behavior is indicative of an attempt to disable or tamper with security tools using kernel-level privileges.