LoFP LoFP / t1543.003

t1543.003

TitleTags
administrative scripts
automated scripts in virtualized environments for device cleanup.
container runtimes or security tools during initialization
device creation by legitimate scripts or init systems (udevadm, makedev)
false positives may occur if one of the vulnerable driver names mentioned above didn't change its name between versions. so always make sure that the driver being loaded is the legitimate one and the non vulnerable version.
if you experience a lot of fp you could comment the driver name or its exact known legitimate location (when possible)
installation of a service
legitimate administrator or user creates a service for legitimate reasons.
legitimate driver development, testing, or administrative troubleshooting (e.g., enabling/disabling hardware)
legitimate use of psservice by an administrator
legitimate use of the tool
legitimate vmware administration, tools installation/uninstallation, or troubleshooting driver conflicts.
rare legitimate installation of kernel drivers via sc.exe
software installation
the rule doesn't look for anything suspicious so false positives are expected. if you use one of the tools mentioned, comment it out
there is a relevant set of false positives depending on applications in the environment
unknown
unlikely