name: Windows Service Create Kernel Mode Driver id: 0b4e3b06-1b2b-4885-b752-cf06d12a90cb version: 1 date: '2022-05-05' author: Michael Haag, Splunk status: production type: TTP description: The following analytic identifes a new kernel driver being added to Windows using sc.exe. Adding a Kernel driver is not common day to day and should be investigated to further understand the source. data_source: - Sysmon Event ID 1 search: selection1: CommandLine: '*kernel*' Image|endswith: sc.exe condition: selection1 how_to_implement: To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. known_false_positives: False positives may be present based on common applications adding new drivers, however, filter as needed. references: - https://www.aon.com/cyber-solutions/aon_cyber_labs/yours-truly-signed-av-driver-weaponizing-an-antivirus-driver/ tags: analytic_story: - Windows Drivers - CISA AA22-320A asset_type: Endpoint confidence: 80 impact: 60 message: Service control, $process_name$, loaded a new kernel mode driver on $dest$ by $user$. mitre_attack_id: - T1543.003 - T1543 - T1068 observable: - name: user type: User role: - Victim - name: dest type: Hostname role: - Victim product: - Splunk Enterprise - Splunk Enterprise Security - Splunk Cloud risk_score: 48 security_domain: endpoint tests: - name: True Positive Test attack_data: - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1068/drivers/sc_kernel.log source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: xmlwineventlog update_timestamp: true