LoFP LoFP / t1014


false positives are present based on automated tooling or system administrative usage. filter as needed.
false positives may be present based on legitimate third party applications needing to install drivers. filter, or allow list known good drivers consistently being installed in these paths.
this analytic is meant to assist with identifying and hunting drivers loaded in the environment.