Log source category
driver_load log source Sigma rules
10 Sigma detection rules in the library use the driver_load log source, mostly on windows. The driver_load category groups related telemetry so you can find detections that consume the same events. Open a rule to read its detection logic, MITRE ATT&CK mapping and original YAML.
Driver Load From A Temporary Directory
highDetects a driver load from a temporary directory
windows
Malicious Driver Load
highDetects loading of known malicious drivers via their hash.
windows
PUA - Process Hacker Driver Load
highDetects driver load of the Process Hacker tool
windows
Vulnerable Driver Load
highDetects loading of known vulnerable drivers via their hash.
windows
Vulnerable HackSys Extreme Vulnerable Driver Load
highDetects the load of HackSys Extreme Vulnerable Driver which is an intentionally vulnerable Windows driver developed for security enthusiasts to learn and polish their exploitation skills at Kernel level and often abused by threat actors
windows
Vulnerable WinRing0 Driver Load
highDetects the load of a signed WinRing0 driver often used by threat actors, crypto miners (XMRIG) or malware for privilege escalation
windows
WinDivert Driver Load
highDetects the load of the Windiver driver, a powerful user-mode capture/sniffing/modification/blocking/re-injection package for Windows
windows
Malicious Driver Load By Name
mediumDetects loading of known malicious drivers via the file name of the drivers.
windows
PUA - System Informer Driver Load
mediumDetects driver load of the System Informer tool
windows
Vulnerable Driver Load By Name
lowDetects the load of known vulnerable drivers via the file name of the drivers.
windows