Rule Info
Name
Suspicious Driver Service Installation - System
Author
Swachchhanda Shrawan Poudel (Nextron Systems)
Description
Detects driver service installations from suspicious locations, indicating potential malware activity.
Threat actors may install malicious/vulnerable drivers for various purposes, such as to bypass security products (EDR/AV) or gain kernel access to dump lsass etc.
This technique is very commonly used in security product bypass attempts and is nowadays commonly used by ransomware groups/threat actors.
Date
2026-01-27 00:00:00
Modified
None
Id
f6f9095a-f2b2-4b69-ba19-92f1a2cd8c7e
Tags
attack.defense-evasion attack.t1562.001
Type
Nextron Sigma feed only (private)
