← Back to driver explorer
Driver intelligenceVulnerableVerified
thelper.sys
OCular THelper driver with arbitrary kernel memory read/write and process manipulation capabilities. Identified in ESET EDR killers research (March 2026) with 46 execution parents linked to AgentStp campaigns abusing the driver to disable EDR products.
Known samples 1
0 recorded TRUE · 0 recorded FALSE · 1 unknown for loading despite HVCI. Results apply to individual samples.
thelper.sysSample 1 · HVCI unknown
- MD5
0f5b41e746b09c740e57c0262edbd140- SHA1
6ee94f6bdc4c4ed0fff621fec36c70ff093659ed- SHA256
7e783b0a0ff4710306bb3bca29296cf962ae77abc81245a99f12a9039158226f- Imphash
9823fa9dc48fb8be6f585ea4c49bdb7e- Authentihash MD5
fff1ff5603c26272f633b8899888fbad- Authentihash SHA1
33f90e874ba571db4ba40e173c4dfbdb6da28378- Authentihash SHA256
014b08b368700360821dc007724afe3f4305bf5fbe09fc0d24f5865f19ace197- Machine
- AMD64
- Version
- 4, 71, 408, 0
- Publisher
- TEC Solutions Limited.
Recorded command
sc.exe create thelper.sys binPath=C:\windows\temp\thelper.sys type=kernel && sc.exe start thelper.sysElevate privileges · Privileges: kernel · OS: Windows 10
Research & references
Acknowledgement: ESET Research @ESETresearch

