Analytics BIOC
Low
✕
Uncommon driver loaded
An uncommon driver loaded which may be an attempt to kill the EDR or install rootkit.
- Module:
- Platform Analytics
- Data source:
- XDR Agent
ATT&CK tactics: Defense Evasion (TA0005)
ATT&CK techniques: Rootkit (T1014)
Attacker's goals:
Install rootkit to gain kernel-level to gain full control over the machine or disable security products.
Investigative actions:
Investigate which process created the driver or how it has been loaded.
- Test period:
- N/A (single event)
- Deduplication:
- 1 Day
3 variations:
- Uncommon driver loaded by a Web server process High (parent: Low)
- Globally rare and unsigned driver loaded Medium (parent: Low)
- Uncommon driver with a globally rare vendor loaded as a service Medium (parent: Low)