LoFP LoFP / pnputil.exe being used may be performed by a system administrator.

Techniques

Sample rules

Suspicious Driver Install by pnputil.exe

Description

Detects when a possible suspicious driver is being installed via pnputil.exe lolbin

Detection logic

condition: selection
selection:
  CommandLine|contains:
  - -i
  - /install
  - -a
  - /add-driver
  - '.inf'
  Image|endswith: \pnputil.exe