BIOC Informational

Fltmc.exe used to unload filter driver

Attackers can abuse the Filter Manager Control Program (fltMC.exe) to unload MiniFilter drivers, some of which may be used for activity monitoring.

Module:
Platform Analytics
Agent event type:
Process execution
Category:
Evasion
Status:
Enabled
ATT&CK tactics: Defense Evasion (TA0005)
ATT&CK techniques: Impair Defenses: Disable or Modify Tools (T1562.001)
Indicator:

Process action type = execution AND target process cmd = * unload * AND target process name = fltmc.exe

Preventable: yes