Vulnerable WinRing0 Driver Load — Detection Rule

Detects the load of a signed WinRing0 driver often used by threat actors, crypto miners (XMRIG) or malware for privilege escalation

Read the full analysis on IntelFusions