DriverQuery.EXE Execution

Rule Info

Name
DriverQuery.EXE Execution
Author
Nasreddine Bencherchali (Nextron Systems)
Description
Detect usage of the "driverquery" utility. Which can be used to perform reconnaissance on installed drivers
Date
2023-01-19 00:00:00
Modified
2023-09-29 00:00:00
Id
a20def93-0709-4eae-9bd2-31206e21e6b2
Tags
attack.discovery
Type
Community Rule

Rule History

Author
Title
Date
Commit
Nasreddine Bencherchali
Merge PR #4950 from @nasbench - Comply With v2 Spec Changes
2024-08-12
github-actions[bot]
Merge PR #4942 from @nasbench - promote older rules status from experimental to test
2024-08-01
Nasreddine Bencherchali
Merge PR #4482 From @nasbench - Add New Automation Workflows
2023-10-18
Nasreddine Bencherchali
Merge PR #4427 from @nasbench - Multiple Fixes & Enhancements
2023-10-04
Nasreddine Bencherchali
feat: more fixes and updates
2023-02-05
Nasreddine Bencherchali
chore: add nextron authors tag
2023-02-01
Nasreddine Bencherchali
fix: driverquery condition and selection
2023-01-19
Nasreddine Bencherchali
feat: new rules for driverquery
2023-01-19