Tamper Defense Evasion Windows Unloads a driver used by security agents Use Defense evasion fltMC.exe unload SysmonDrv copy Contextadmin NativeTamper MITRET1562.001 DetectionSigma: github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_fltmc_unload_driver_sysmon.ymlElastic: github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/defense_evasion_via_filter_manager.tomlSplunk: github.com/splunk/security_content/blob/18f63553a9dc1a34122fa123deae2b2f9b9ea391/detections/endpoint/unload_sysmon_filter_driver.ymlIOC: 4688 events with fltMC.exe Refswww.darkoperator.com/blog/2018/10/5/operating-offensively-against-sysmonlolbas-project.github.io/lolbas/Binaries/fltMC/