Detection rules › Sigma

CodeIntegrity - Unsigned Kernel Module Loaded

Severity
high
Author
Nasreddine Bencherchali (Nextron Systems)
Source
upstream

Detects the presence of a loaded unsigned kernel module on the system.

Event coverage

ProviderEvent IDTitle
CodeIntegrity3001Code Integrity determined an unsigned kernel module FileNameBuffer is loaded into the system.

Stages and Predicates

Stage 1: selection