Detection rules › Sigma

CodeIntegrity - Revoked Kernel Driver Loaded

Severity
high
Author
Nasreddine Bencherchali (Nextron Systems)
Source
upstream

Detects the load of a revoked kernel driver

Event coverage

ProviderEvent IDTitle
CodeIntegrity3021Code Integrity determined a revoked kernel module FileNameBuffer is loaded into the system.
CodeIntegrity3022Code Integrity determined a revoked kernel module FileNameBuffer is loaded into the system.

Stages and Predicates

Stage 1: selection