BIOC
Informational
✕
Fltmc.exe used to unload filter driver
Attackers can abuse the Filter Manager Control Program (fltMC.exe) to unload MiniFilter drivers, some of which may be used for activity monitoring.
- Module:
- Platform Analytics
- Agent event type:
- Process execution
- Category:
- Evasion
- Status:
- Enabled
ATT&CK tactics: Defense Evasion (TA0005)
ATT&CK techniques: Impair Defenses: Disable or Modify Tools (T1562.001)
Indicator:
Process action type = execution AND target process cmd = * unload * AND target process name = fltmc.exe
Preventable: yes