Rule Info
Name
Disable Input Devices via Disable-PnpDevice - ScriptBlock
Author
Swachchhanda Shrawan Poudel (Nextron Systems)
Description
Detects usage of Disable-PnpDevice PowerShell cmdlet to disable input devices such as keyboards and mouse.
Adversaries may disable input devices to prevent user interaction with the system, facilitating further malicious activities without interruption.
This technique can be part of a broader strategy to maintain persistence or evade detection by hindering user access.
Date
2026-03-22 00:00:00
Modified
None
Id
17d2820b-4d8c-49b9-b039-a3dfa676fa70
Tags
attack.defense-evasion attack.t1562.001 attack.impact
Type
Nextron Sigma feed only (private)
