Rule Info
Name
Disable Input Devices via Disable-PnpDevice
Author
Swachchhanda Shrawan Poudel (Nextron Systems)
Description
Detects usage of Disable-PnpDevice PowerShell cmdlet to disable crucial input devices such as keyboards and mouse.
Adversaries may disable input devices to prevent user interaction with the system, facilitating further malicious activities without interruption.
This technique can be part of a broader strategy to maintain persistence or evade detection by hindering user access.
Date
2026-03-22 00:00:00
Modified
None
Id
2b0670cc-0dba-43c7-a5dd-3ef8ea12597c
Tags
attack.defense-evasion attack.t1562.001 attack.impact
Type
Nextron Sigma feed only (private)
