Suspicious pnputil.exe Driver Installation via .inf on Windows

Flags pnputil.exe command lines indicating driver install/add actions targeting .inf files on Windows.

FreeUnreviewedSigmamediumv1
title: Suspicious pnputil.exe Driver Installation via .inf on Windows
id: 956c330f-0464-4d13-8d76-2e7096e37e37
status: test
description: This rule identifies process executions where pnputil.exe is used with command-line parameters indicative of installing or adding a driver for a specified .inf file. Such activity matters because driver installation can be used for persistence or to elevate control over the system. It relies on Windows process creation telemetry capturing the executed image path and the full command line.
references:
  - https://learn.microsoft.com/en-us/windows-hardware/drivers/devtest/pnputil-command-syntax
  - https://strontic.github.io/xcyclopedia/library/pnputil.exe-60EDC5E6BDBAEE441F2E3AEACD0340D2.html
  - https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_lolbin_susp_driver_installed_by_pnputil.yml
author: Hai Vaknin @LuxNoBulIshit, Avihay eldad  @aloneliassaf, Austin Songer @austinsonger, Huntrule Team
date: 2021-09-30
modified: 2022-10-09
tags:
  - attack.privilege-escalation
  - attack.persistence
  - attack.t1547
logsource:
  category: process_creation
  product: windows
detection:
  selection:
    CommandLine|contains:
      - -i
      - /install
      - -a
      - /add-driver
      - ".inf"
    Image|endswith: \pnputil.exe
  condition: selection
falsepositives:
  - Pnputil.exe being used may be performed by a system administrator.
  - Verify whether the user identity, user agent, and/or hostname should be making changes in your environment.
  - Pnputil.exe being executed from unfamiliar users should be investigated. If known behavior is causing false positives, it can be exempted from the rule.
level: medium
license: DRL-1.1
related:
  - id: a2ea3ae7-d3d0-40a0-a55c-25a45c87cac1
    type: derived

What it detects

This rule identifies process executions where pnputil.exe is used with command-line parameters indicative of installing or adding a driver for a specified .inf file. Such activity matters because driver installation can be used for persistence or to elevate control over the system. It relies on Windows process creation telemetry capturing the executed image path and the full command line.

Known false positives

  • Pnputil.exe being used may be performed by a system administrator.
  • Verify whether the user identity, user agent, and/or hostname should be making changes in your environment.
  • Pnputil.exe being executed from unfamiliar users should be investigated. If known behavior is causing false positives, it can be exempted from the rule.

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.