Suspicious Driver Install by pnputil.exe (a2ea3ae7-d3d0-40a0-a55c-25a45c87cac1)
Detects when a possible suspicious driver is being installed via pnputil.exe lolbin
| Cluster A | Galaxy A | Cluster B | Galaxy B | Level |
|---|---|---|---|---|
| Suspicious Driver Install by pnputil.exe (a2ea3ae7-d3d0-40a0-a55c-25a45c87cac1) | Sigma-Rules | Boot or Logon Autostart Execution - T1547 (1ecb2399-e8ba-4f6b-8ba7-5c27d49405cf) | Attack Pattern | 1 |