Suspicious Driver Service Installation - Security

Rule Info

Name
Suspicious Driver Service Installation - Security
Author
Swachchhanda Shrawan Poudel (Nextron Systems)
Description
Detects installations of driver services from unusual directories that may indicate malicious activity. Adversaries often deploy rogue or compromised drivers to evade security measures (like EDR/AV), obtain kernel-level access, or extract sensitive data like LSASS memory. This approach has become increasingly prevalent among ransomware operators and malicious actors.
Date
2026-01-27 00:00:00
Modified
None
Id
d0e0274c-7df8-46b1-a2b5-a804e43a2d17
Tags
attack.defense-evasion attack.t1562.001
Type
Nextron Sigma feed only (private)

Rule History