Windows: Suspicious Driver Installation via pnputil.exe

Flags pnputil.exe command lines indicating driver install/add actions targeting .inf files on Windows.

FreeReviewedSigma · Medium · v2
Product
windows
Category
process_creation
Author
Hai Vaknin @LuxNoBulIshit, Avihay eldad @aloneliassaf, Austin Songer @austinsonger (SigmaHQ), DRL 1.1
Published
2021-09-30
Updated
2026-07-31
title: "Windows: Suspicious Driver Installation via pnputil.exe"
id: 956c330f-0464-4d13-8d76-2e7096e37e37
status: test
description: This rule flags process creation events where pnputil.exe is used to install or add a driver .inf file, indicated by command-line arguments such as -i, /install, -a, /add-driver, and the .inf extension. Installing drivers can be abused to achieve persistence or elevate capabilities, so monitoring this pattern helps catch non-administrative driver deployment attempts. It relies on Windows process creation telemetry, specifically the executable path ending with \pnputil.exe and matching command-line substrings.
references:
  - https://learn.microsoft.com/en-us/windows-hardware/drivers/devtest/pnputil-command-syntax
  - https://strontic.github.io/xcyclopedia/library/pnputil.exe-60EDC5E6BDBAEE441F2E3AEACD0340D2.html
  - https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_lolbin_susp_driver_installed_by_pnputil.yml
author: Hai Vaknin @LuxNoBulIshit, Avihay eldad  @aloneliassaf, Austin Songer @austinsonger, Huntrule Team
date: 2021-09-30
modified: 2022-10-09
tags:
  - attack.privilege-escalation
  - attack.persistence
  - attack.t1547
logsource:
  category: process_creation
  product: windows
detection:
  selection:
    CommandLine|contains:
      - -i
      - /install
      - -a
      - /add-driver
      - ".inf"
    Image|endswith: \pnputil.exe
  condition: selection
falsepositives:
  - Pnputil.exe being used may be performed by a system administrator.
  - Verify whether the user identity, user agent, and/or hostname should be making changes in your environment.
  - Pnputil.exe being executed from unfamiliar users should be investigated. If known behavior is causing false positives, it can be exempted from the rule.
level: medium
license: DRL-1.1
related:
  - id: a2ea3ae7-d3d0-40a0-a55c-25a45c87cac1
    type: derived