LiveKD Driver Creation By Uncommon Process

Rule Info

Name
LiveKD Driver Creation By Uncommon Process
Author
Nasreddine Bencherchali (Nextron Systems)
Description
Detects the creation of the LiveKD driver by a process image other than "livekd.exe".
Reference
Internal Research
Date
2023-05-16 00:00:00
Modified
None
Id
059c5af9-5131-4d8d-92b2-de4ad6146712
Tags
attack.defense_evasion attack.privilege_escalation DEMO
Type
Community Rule

Rule History

Author
Title
Date
Commit
github-actions[bot]
Merge PR #4791 from @nasbench - Promote older rules status from `experimental` to `test`
2024-04-01
Nasreddine Bencherchali
feat: multiple updates and new rules (#4242)
2023-05-17