Driver Service Configuration Changed to Kernel Mode

Rule Info

Name
Driver Service Configuration Changed to Kernel Mode
Author
Swachchhanda Shrawan Poudel (Nextron Systems)
Description
Detects attempts to modify driver's service configurations to kernel mode using the 'sc config' command. An attacker can use sc.exe to change the privileges for a driver, enabling it to run in kernel mode, which is typically performed by attackers in order to gain deeper system control to disable security services such as antivirus protection.
Date
2026-01-27 00:00:00
Modified
None
Id
678fd7f4-80ef-4104-aa2e-7bb249f613c1
Tags
attack.defense-evasion attack.t1562.001
Type
Nextron Sigma feed only (private)

Rule History