title: Filter Driver Unloaded Via Fltmc.EXE id: 4931188c-178e-4ee7-a348-39e8a7a56821 related: - id: 4d7cda18-1b12-4e52-b45c-d28653210df8 # Sysmon specific type: derived status: test description: Detect filter driver unloading activity via fltmc.exe references: - https://www.darkoperator.com/blog/2018/10/5/operating-offensively-against-sysmon - https://www.cybereason.com/blog/threat-analysis-report-lockbit-2.0-all-paths-lead-to-ransom author: Nasreddine Bencherchali (Nextron Systems) date: 2023-02-13 modified: 2025-10-07 tags: - attack.stealth - attack.defense-impairment - attack.t1070 - attack.t1685 - attack.t1685.001 logsource: product: windows category: process_creation detection: selection_img: - Image|endswith: '\fltMC.exe' - OriginalFileName: 'fltMC.exe' selection_cli: CommandLine|contains: 'unload' filter_optional_avira: ParentImage|contains: - '\AppData\Local\Temp\' - ':\Windows\Temp\' ParentImage|endswith: '\endpoint-protection-installer-x64.tmp' CommandLine|endswith: - 'unload rtp_filesystem_filter' - 'unload rtp_filter' filter_optional_manageengine: ParentImage: 'C:\Program Files (x86)\ManageEngine\uems_agent\bin\dcfaservice64.exe' CommandLine|endswith: 'unload DFMFilter' condition: all of selection_* and not 1 of filter_optional_* falsepositives: - Unknown level: medium