Malicious Vulnerable Driver Mapping via KDU

PremiumReviewedSigma · High · v1
Product
windows
Category
process_creation
Author
HuntRule
Published
2026-09-30
Updated
2026-09-30

ATT&CK techniques

Priv Esc → Defense Evasion
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Defense Evasion

  7. Cred Access

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule detects execution of the Kernel Driver Utility kdu.exe with its provider and driver-mapping flags, a bring-your-own-vulnerable-driver technique observed in the ESXi exploitation activity to load unsigned kernel code. KDU abuses a signed vulnerable driver to map an attacker driver such as MyDriver.sys into the kernel, defeating driver signature enforcement. Presence of kdu.exe with these arguments indicates kernel-level defense evasion.

Related detections9 linkedT1068 — drag to rearrange
Malicious Vulnerable Driver Load via TfSysMon.sys BYOVD (via driver_load)
Malicious Vulnerable Driver Load by GentleKiller BYOVD EDR Killer
Malicious JuicyPotatoNG Privilege Escalation Tool Execution from Public Directory (via process_creation)
Suspicious Kernel Module Load From World Writable Directory on Linux
Malicious Print Spooler Child Process Execution via PrintNightmare (via process_creation)
Suspicious Kernel Module Load Or Unload For Rootkit Deployment via PUMAKIT
Suspicious Fileless Execution From Memory File Descriptor via PUMAKIT
Suspicious Modification of etc passwd Following Linux Kernel Exploit
Malicious ABYSSWORKER EDR-Killer Driver Load via smuol.sys
Malicious Vulnerable Driver Mapping via KDU
Pivot detection · T1068 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.