Detection rules › Sigma

Suspicious Driver Install by pnputil.exe

Severity
medium
Author
Hai Vaknin @LuxNoBulIshit, Avihay eldad @aloneliassaf, Austin Songer @austinsonger
Source
upstream

Detects when a possible suspicious driver is being installed via pnputil.exe lolbin

MITRE ATT&CK coverage

TacticTechniques
PersistenceT1547 Boot or Logon Autostart Execution
Privilege EscalationT1547 Boot or Logon Autostart Execution

Event coverage

ProviderEvent IDTitle
Sysmon1Process creation
Security-Auditing4688A new process has been created.

Stages and Predicates

Stage 1: selection

or:
CommandLine|contains: -a
CommandLine|contains: -i
CommandLine|contains: .inf
CommandLine|contains: '/add-driver'
CommandLine|contains: '/install'
Image|endswith: '\pnputil.exe'

Indicators

Each row is a field, operator, and value that the rule matches. The corpus column counts how many other rules in the catalog look for the same combination: high numbers point to widely-used, community-vetted indicators. Blank or 1 shows that the indicator is specific to this rule.

FieldKindValues
CommandLinematch
  • -a corpus 4 (sigma 4)
  • -i corpus 6 (sigma 6)
  • .inf corpus 3 (sigma 3)
  • /add-driver
  • /install
Imageends_with
  • \pnputil.exe