Rule Info
Name
Kernel Driver Service ImagePath Set by Potentially Suspicious Process
Author
Swachchhanda Shrawan Poudel (Nextron Systems)
Description
Detects kernel driver service ImagePath registry values being set by potentially suspicious processes.
This can indicate attempts to load kernel drivers without using the standard Service Control Manager,
which malware may use to maintain persistence or employ BYOVD techniques often used in EDR killer tools.
It's recommended to first baseline this rule in your environment and adjust it accordingly before enabling
it in production.
Date
2026-09-02 00:00:00
Modified
None
Id
7f1b3d84-2c6e-4a57-d9f2-4b0e8c1a6395
Tags
attack.privilege-escalation attack.persistence attack.t1543.003
Type
Nextron Sigma feed only (private)
