Title:
Suspicious Driver Install by pnputil.exe
Status:
test
Description:Detects when a possible suspicious driver is being installed via pnputil.exe lolbin
References:
-https://learn.microsoft.com/en-us/windows-hardware/drivers/devtest/pnputil-command-syntax
-https://strontic.github.io/xcyclopedia/library/pnputil.exe-60EDC5E6BDBAEE441F2E3AEACD0340D2.html
Author: Hai Vaknin @LuxNoBulIshit, Avihay eldad @aloneliassaf, Austin Songer @austinsonger
Date: 2021-09-30
modified:2022-10-09
Tags:
- -'attack.privilege-escalation'
- -'attack.persistence'
- -'attack.t1547'
Logsource:
- category: process_creation
- product: windows
Detection:
selection:
CommandLine|contains:
-'-i'
-'/install'
-'-a'
-'/add-driver'
-'.inf'
Image|endswith:
'\pnputil.exe'
condition:
selection
Falsepositives:
-Pnputil.exe being used may be performed by a system administrator.
-Verify whether the user identity, user agent, and/or hostname should be making changes in your environment.
-Pnputil.exe being executed from unfamiliar users should be investigated. If known behavior is causing false positives, it can be exempted from the rule.
Level:
medium