Detection rules › Kusto
Microsoft Recommended Driver Block List
The query below detects loading or creation of a vulnerable driver that is listed in the Microsoft recommended driver block rules.
MITRE ATT&CK coverage
| Tactic | Techniques |
|---|---|
| Stealth | No specific technique |
References
Telemetry coverage
Rule body
// Author: Cyb3rMonk(https://twitter.com/Cyb3rMonk, https://academy.bluraven.io)
//
// Query parameters:
let driver_block_list = externaldata (driver:dynamic) [@"https://raw.githubusercontent.com/Cyb3r-Monk/Microsoft-Vulnerable-Driver-Block-Lists/refs/heads/main/msft_vuln_driver_block_list.json"]
with (format=multijson, ingestionMapping='[{"Column":"driver","Properties":{"Path":"$"}}]')
| evaluate bag_unpack(driver)
;
let driver_hashes = toscalar(
driver_block_list
| where isnotempty(FileHash)
| summarize make_set(tolower(FileHash))
)
;
union
(
DeviceEvents
| where ActionType == "DriverLoad"
| where SHA1 in~ (driver_hashes) or SHA256 in~ (driver_hashes)
),
(
DeviceFileEvents
| where SHA1 in~ (driver_hashes) or SHA256 in~ (driver_hashes)
)
Stages and Predicates
Stage 0: let
let driver_block_list = externaldata (driver:dynamic) [@"https://raw.githubusercontent.com/Cyb3r-Monk/Microsoft-Vulnerable-Driver-Block-Lists/refs/heads/main/msft_vuln_driver_block_list.json"]
with (format=multijson, ingestionMapping='[{"Column":"driver","Properties":{"Path":"$"}}]')
| evaluate bag_unpack(driver)
;
let driver_hashes = toscalar(
driver_block_list
| where isnotempty(FileHash)
| summarize make_set(tolower(FileHash))
)
;
Stage 1: union
union of 2 branches
Stage 2: source
DeviceEvents
Stage 3: where
| where ActionType == "DriverLoad"
Stage 4: where
| where SHA1 in~ (driver_hashes) or SHA256 in~ (driver_hashes)
Stage 5: source
DeviceFileEvents
Stage 6: where
| where SHA1 in~ (driver_hashes) or SHA256 in~ (driver_hashes)
Indicators
These rows show field, operator, and value matches.
| Field | Kind | Values | Search |
|---|---|---|---|
ActionType | eq |
| field:"ActionType" kind:eq value:"DriverLoad" |
SHA1 | in |
| field:"sha1" kind:in value:"driver_hashes" |
SHA256 | in |
| field:"sha256" kind:in value:"driver_hashes" |