LiveKD Driver Creation By Uncommon Process

Rule Info

Tags
attack.defense_evasion DEMO attack.privilege_escalation
Name
LiveKD Driver Creation By Uncommon Process
Id
059c5af9-5131-4d8d-92b2-de4ad6146712
Date
2023-05-16 00:00:00
Modified
None
Description
Detects the creation of the LiveKD driver by a process image other than "livekd.exe".
Reference
Internal Research
Author
Nasreddine Bencherchali (Nextron Systems)
Type
Community Rule

Rule History

Title
Author
Commit
Date
feat: multiple updates and new rules (#4242)
Nasreddine Bencherchali
2023-05-17