DriverQuery.EXE Execution

Rule Info

Name
DriverQuery.EXE Execution
Description
Detect usage of the "driverquery" utility. Which can be used to perform reconnaissance on installed drivers
Modified
2023-02-04 00:00:00
Date
2023-01-19 00:00:00
Author
Nasreddine Bencherchali (Nextron Systems)
Tags
attack.discovery DEMO
Id
a20def93-0709-4eae-9bd2-31206e21e6b2
Type
Community Rule

Rule History

Author
Commit
Title
Date
Nasreddine Bencherchali
feat: more fixes and updates
2023-02-05
Nasreddine Bencherchali
chore: add nextron authors tag
2023-02-01
Nasreddine Bencherchali
fix: driverquery condition and selection
2023-01-19
Nasreddine Bencherchali
feat: new rules for driverquery
2023-01-19