XMRig Miner smss.exe Masquerade Outside System32 with WinRing0x64 Driver
Detects execution of an XMRig cryptominer masquerading as the legitimate system process 'smss.exe' from a non-standard file path. This detection specifically identifies the presence of the WinRing0x64.sys kernel driver, often used by XMRig for hardware MSR access, and detects preceding malicious activity involving UnRAR extraction of the miner using a specific password.
Sigma

