Detection rules › Sigma

Device Installation Blocked

Severity
medium
Author
frack113
Source
upstream

Detects an installation of a device that is forbidden by the system policy

MITRE ATT&CK coverage

TacticTechniques
Initial AccessT1200 Hardware Additions

Event coverage

ProviderEvent IDTitle
Security-Auditing6423The installation of this device is forbidden by system policy.

Stages and Predicates

Stage 1: selection