PUA - Kernel Driver Utility (KDU) Execution

 Original Source: [Sigma source]
Title: PUA - Kernel Driver Utility (KDU) Execution
Status: experimental
Description:Detects execution of the Kernel Driver Utility (KDU) tool. KDU can be used to bypass driver signature enforcement and load unsigned or malicious drivers into the Windows kernel. Potentially allowing for privilege escalation, persistence, or evasion of security controls.
References:
  -https://github.com/h4rmy/KDU
  -https://huntress.com/blog/esxi-vm-escape-exploit
Author: Matt Anderson, Dray Agha, Anna Pham (Huntress)
Date: 2026-01-02
modified:None
Tags:
  • -'attack.persistence'
  • -'attack.privilege-escalation'
  • -'attack.t1543.003'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection_img:
    - Image|endswith:
      - '\kdu.exe'
      - '\hamakaze.exe'
OriginalFileName:'hamakaze.exe'   selection_cli_suspicious:
    CommandLine|contains:
      -'-map '
      -'-prv '
      -'-dse '
      -'-ps '

  condition:all of selection_*
Falsepositives:
  -Legitimate driver development, testing, or administrative troubleshooting (e.g., enabling/disabling hardware)
Level: high