LoFP LoFP / pnputil.exe being executed from unfamiliar users should be investigated. if known behavior is causing false positives, it can be exempted from the rule.

Techniques

Sample rules

Suspicious Driver Install by pnputil.exe

Description

Detects when a possible suspicious driver is being installed via pnputil.exe lolbin

Detection logic

condition: selection
selection:
  CommandLine|contains:
  - -i
  - /install
  - -a
  - /add-driver
  - '.inf'
  Image|endswith: \pnputil.exe