Technique T1562
Impair Defenses
Detection & mitigation
Monitor for loading of known vulnerable or abused Microsoft-signed drivers (e.g., via Sysmon Event ID 6 or driver load events) and correlate with process termination of security products. Enforce driver block rules using Windows Defender Application Control or vulnerable driver blocklist to prevent loading of abused drivers.