SigmaHQ/rules/windows/sysmon/sysmon_susp_driver_load.yml

15 lines
403 B
YAML
Raw Normal View History

2017-02-12 14:50:39 +00:00
title: Suspicious Driver Load from Temp
2018-07-10 14:14:37 +00:00
description: Detects a driver load from a temporary directory
author: Florian Roth
logsource:
product: windows
service: sysmon
2017-02-12 14:50:39 +00:00
detection:
selection:
EventID: 6
2019-02-02 23:24:57 +00:00
ImageLoaded: '*\Temp\\*'
2017-02-12 14:50:39 +00:00
condition: selection
falsepositives:
2018-07-13 23:36:12 +00:00
- there is a relevant set of false positives depending on applications in the environment
2017-02-16 17:02:26 +00:00
level: medium