For the complete documentation index, see llms.txt. This page is also available as Markdown.

Uncommon driver loaded

Synopsis

Field
Value

Activation Period

14 Days

Training Period

30 Days

Test Period

N/A (single event)

Deduplication Period

1 Day

Required Data

XDR Agent

ATT&CK Tactic

Stealth (TA0005)

ATT&CK Technique

Rootkit (T1014)

Severity

Low

Description

An uncommon driver loaded which may be an attempt to kill the EDR or install rootkit.

Attacker's Goals

Install rootkit to gain kernel-level to gain full control over the machine or disable security products.

Investigative actions

Investigate which process created the driver or how it has been loaded.

Variations

Uncommon driver loaded by a Web server process

Synopsis

Field
Value

ATT&CK Tactic

Stealth (TA0005)

ATT&CK Technique

Rootkit (T1014)

Severity

High

Description

An uncommon driver loaded which may be an attempt to kill the EDR or install rootkit by a Web server process.

Attacker's Goals

Install rootkit to gain kernel-level to gain full control over the machine or disable security products.

Investigative actions

Investigate which process created the driver or how it has been loaded.

Globally rare and unsigned driver loaded

Synopsis

Field
Value

ATT&CK Tactic

Stealth (TA0005)

ATT&CK Technique

Rootkit (T1014)

Severity

Medium

Description

Globally rare and unsigned driver loaded.

Attacker's Goals

Install rootkit to gain kernel-level to gain full control over the machine or disable security products.

Investigative actions

Investigate which process created the driver or how it has been loaded.

Uncommon driver with a globally rare vendor loaded as a service

Synopsis

Field
Value

ATT&CK Tactic

Stealth (TA0005)

ATT&CK Technique

Rootkit (T1014)

Severity

Medium

Description

An uncommon driver loaded which may be an attempt to kill the EDR or install rootkit.

Attacker's Goals

Install rootkit to gain kernel-level to gain full control over the machine or disable security products.

Investigative actions

Investigate which process created the driver or how it has been loaded.

Was this helpful?