{"id":"295c9289-acee-4503-a571-8eacaef36b28","title":"Vulnerable HackSys Extreme Vulnerable Driver Load","description":"Detects the load of HackSys Extreme Vulnerable Driver which is an intentionally vulnerable Windows driver developed for security enthusiasts to learn and polish their exploitation skills at Kernel level and often abused by threat actors","author":"Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"high","date":"2022-08-18","modified":"2024-11-23","tags":["attack.persistence","attack.privilege-escalation","attack.t1543.003"],"technique_ids":["T1543.003"],"logsource":{"product":"windows","category":"driver_load"},"falsepositives":["Unlikely"],"references":["https://github.com/hacksysteam/HackSysExtremeVulnerableDriver"],"source_path":"rules/windows/driver_load/driver_load_win_vuln_hevd_driver.yml","source_sha256":"cf1bf672c43d4441366c47bb9ce70bf3dfd3bff927951d8bf932483350dfe20a","source_url":"https://github.com/anpa1200/sigma/blob/b249e9683190cffdcaf188ccbfb90bf4759844e1/rules/windows/driver_load/driver_load_win_vuln_hevd_driver.yml","license":"Detection Rule License 1.1","license_url":"https://github.com/SigmaHQ/Detection-Rule-License/blob/main/LICENSE.Detection.Rules.md","yaml":"title: Vulnerable HackSys Extreme Vulnerable Driver Load\nid: 295c9289-acee-4503-a571-8eacaef36b28\nstatus: test\ndescription: Detects the load of HackSys Extreme Vulnerable Driver which is an intentionally vulnerable Windows driver developed for security enthusiasts to learn and polish their exploitation skills at Kernel level and often abused by threat actors\nreferences:\n    - https://github.com/hacksysteam/HackSysExtremeVulnerableDriver\nauthor: Nasreddine Bencherchali (Nextron Systems)\ndate: 2022-08-18\nmodified: 2024-11-23\ntags:\n    - attack.persistence\n    - attack.privilege-escalation\n    - attack.t1543.003\nlogsource:\n    product: windows\n    category: driver_load\ndetection:\n    selection:\n        - ImageLoaded|endswith: '\\HEVD.sys'\n        - Hashes|contains:\n              - 'IMPHASH=f26d0b110873a1c7d8c4f08fbeab89c5' # Version 3.0\n              - 'IMPHASH=c46ea2e651fd5f7f716c8867c6d13594' # Version 3.0\n    condition: selection\nfalsepositives:\n    - Unlikely\nlevel: high\n","validation":"yaml_parsed_not_backend_compiled_or_live_validated","techniques":[{"key":"enterprise/T1543.003","id":"T1543.003","name":"Windows Service","page":"techniques/enterprise/T1543.003/"}],"data_path":"data/detection-rules/295c9289-acee-4503-a571-8eacaef36b28.json","kind":"sigma"}
