Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

Qilin – Vulnerable Driver Load for EDR Kill (BYOVD)

Qilin Defense Evasion Sentinel
MITRE ATT&CK
Exploitation for Stealth
Data Source
DeviceEvents
Date Added
2026-07-23
Last Updated
2026-07-23
Source
ransomware.live group_tools dataset (qilin)
What This Detects
Flags loading of the Zemana Anti-Rootkit or Toshiba power-management drivers, or invocation of EDRSandBlast – the BYOVD chain Qilin affiliates use to blind/kill EDR before deploying the encryptor.
Query
DeviceEvents
| where Timestamp > ago(1d)
| where ActionType in ("DriverLoad","ServiceInstalled")
| where FileName has_any ("zam64.sys","zamguard.sys","tvalz.sys","tvalzkmd.sys")
   or InitiatingProcessCommandLine has_any ("EDRSandBlast","-driver load","PowerTool")
| project Timestamp, DeviceName, FileName, FolderPath, InitiatingProcessCommandLine, InitiatingProcessAccountName

Hunting queries are starting points for threat hunting & detection engineering — validate table/column names against your own workspace schema and tune thresholds before turning any of these into a production alert rule.