Skip to content

Commit 6153657

Browse files
tccontrenasbench
andauthored
Update detections/endpoint/windows_service_create_kernel_mode_driver.yml
Co-authored-by: Nasreddine Bencherchali <[email protected]>
1 parent a1702c6 commit 6153657

File tree

1 file changed

+1
-0
lines changed

1 file changed

+1
-0
lines changed

detections/endpoint/windows_service_create_kernel_mode_driver.yml

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -44,6 +44,7 @@ known_false_positives: False positives may be present based on common applicatio
4444
references:
4545
- https://www.aon.com/cyber-solutions/aon_cyber_labs/yours-truly-signed-av-driver-weaponizing-an-antivirus-driver/
4646
- https://whiteknightlabs.com/2025/11/25/discreet-driver-loading-in-windows/
47+
- https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/sc-config
4748
drilldown_searches:
4849
- name: View the detection results for - "$user$" and "$dest$"
4950
search: '%original_detection_search% | search user = "$user$" dest = "$dest$"'

0 commit comments

Comments
 (0)