PUA - WinDivert Driver Load

Rule Info

Name
PUA - WinDivert Driver Load
Author
Nasreddine Bencherchali (Nextron Systems)
Description
Detects loading of the WinDivert driver and DLL. While this driver isn't malicious by nature, it can be abused by nefarious actors in order to mute communication between a security solution running on an endpoint and its management console. It achieves this using the Windows Filtering Platform API.
Date
2024-07-04 00:00:00
Modified
None
Id
36424781-4211-47bb-99de-bd52e6a0a5ec
Tags
attack.defense-evasion
Type
Nextron Sigma feed only (private)

Rule History