![Back to home Valhalla Logo](/static/valhalla-logo.png)
Rule Info
Name
LiveKD Driver Creation By Uncommon Process
Author
Nasreddine Bencherchali (Nextron Systems)
Description
Detects the creation of the LiveKD driver by a process image other than "livekd.exe".
Reference
Internal Research
Date
2023-05-16 00:00:00
Modified
None
Id
059c5af9-5131-4d8d-92b2-de4ad6146712
Tags
attack.defense_evasion attack.privilege_escalation DEMO
Type
Community Rule
Link to Public Repo