Vulnerable WinRing0 Driver Load

 Original Source: [Sigma source]
Title: Vulnerable WinRing0 Driver Load
Status: test
Description:Detects the load of a signed WinRing0 driver often used by threat actors, crypto miners (XMRIG) or malware for privilege escalation
References:
  -https://github.com/xmrig/xmrig/tree/master/bin/WinRing0
  -https://www.rapid7.com/blog/post/2021/12/13/driver-based-attacks-past-and-present/
Author: Florian Roth (Nextron Systems)
Date: 2022-07-26
modified:2024-11-23
Tags:
  • -'attack.persistence'
  • -'attack.privilege-escalation'
  • -'attack.t1543.003'
Logsource:
  • product: windows
  • category: driver_load
Detection:
  selection:
Hashes|contains:'IMPHASH=D41FA95D4642DC981F10DE36F4DC8CD7'     - ImageLoaded|endswith:
      - '\WinRing0x64.sys'
      - '\WinRing0.sys'
      - '\WinRing0.dll'
      - '\WinRing0x64.dll'
      - '\winring00x64.sys'
  condition:selection
Falsepositives:
  -Unknown
Level: high