Device Driver Discovery T1652

Tactic: Discovery

Adversaries may attempt to enumerate local device drivers on a victim host. Information about device drivers may highlight various insights that shape follow-on behaviors, such as the function/purpose of the host, present security tools (i.e. Security Software Discovery) or other defenses (e.g., Virtualization/Sandbox Evasion), as well as potential exploitable vulnerabilities (e.g., Exploitation for Privilege Escalation).

Authoring guide

These 1 rule share fields, values, and exclusions.

Fields filtered most (2 distinct)

These fields appear most often in rule filters.

FieldRulesHowSample values
operationName1eq 1compliance
properties.AlertType1eq 1managed device not compliant

Top indicator values (2 distinct)

These values appear most often in rule predicates.

FieldKindValueRules (here)Corpus reach
operationNameeq
compliance
1
properties.AlertTypeeq
managed device not compliant
1

Rules under this technique

These vendors publish rules tagged with this technique.

Platform: Intune

Domain: SaaS

Panther 1 rule