Hide Navigation Hide TOC Sysmon Driver Unloaded Via Fltmc.EXE (4d7cda18-1b12-4e52-b45c-d28653210df8) Detects possible Sysmon filter driver unloaded via fltmc.exe Cluster A Galaxy A Cluster B Galaxy B Level Disable or Modify Tools - T1685 (bbde9781-60aa-4b8a-a911-895b0c1b3872) Attack Pattern Sysmon Driver Unloaded Via Fltmc.EXE (4d7cda18-1b12-4e52-b45c-d28653210df8) Sigma-Rules 1 Sysmon Driver Unloaded Via Fltmc.EXE (4d7cda18-1b12-4e52-b45c-d28653210df8) Sigma-Rules Disable or Modify Windows Event Log - T1685.001 (1411e6b8-80a6-4465-9909-54eaa9c67ce0) Attack Pattern 1 Sysmon Driver Unloaded Via Fltmc.EXE (4d7cda18-1b12-4e52-b45c-d28653210df8) Sigma-Rules Indicator Removal - T1070 (799ace7f-e227-4411-baa0-8868704f2a69) Attack Pattern 1 Disable or Modify Tools - T1685 (bbde9781-60aa-4b8a-a911-895b0c1b3872) Attack Pattern Disable or Modify Windows Event Log - T1685.001 (1411e6b8-80a6-4465-9909-54eaa9c67ce0) Attack Pattern 2