Windows: Suspicious Driver Installation via pnputil.exe
Flags pnputil.exe command lines indicating driver install/add actions targeting .inf files on Windows.
- Product
- windows
- Category
- process_creation
- Author
- Hai Vaknin @LuxNoBulIshit, Avihay eldad @aloneliassaf, Austin Songer @austinsonger (SigmaHQ), DRL 1.1
- Published
- 2021-09-30
- Updated
- 2026-07-31
ATT&CK techniques
Persistence → Priv EscRecon
Resource Dev
Initial Access
Execution
Persistence
Defense Evasion
Cred Access
Discovery
Lateral Movement
Collection
C2
Exfiltration
Impact
What it detects
This rule flags process creation events where pnputil.exe is used to install or add a driver .inf file, indicated by command-line arguments such as -i, /install, -a, /add-driver, and the .inf extension. Installing drivers can be abused to achieve persistence or elevate capabilities, so monitoring this pattern helps catch non-administrative driver deployment attempts. It relies on Windows process creation telemetry, specifically the executable path ending with \pnputil.exe and matching command-line substrings.
Reporting behind it
- learn.microsoft.comhttps://learn.microsoft.com/en-us/windows-hardware/drivers/devtest/pnputil-command-syntax
- strontic.github.iohttps://strontic.github.io/xcyclopedia/library/pnputil.exe-60EDC5E6BDBAEE441F2E3AEACD0340D2.html
- github.comhttps://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_lolbin_susp_driver_installed_by_pnputil.yml
Changelog
v2- v2Candidate ingested via manual entry.2026-07-31
- v1No changelog recorded for this version.2026-07-30
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.
title: "Windows: Suspicious Driver Installation via pnputil.exe"
id: 956c330f-0464-4d13-8d76-2e7096e37e37
status: test
description: This rule flags process creation events where pnputil.exe is used to install or add a driver .inf file, indicated by command-line arguments such as -i, /install, -a, /add-driver, and the .inf extension. Installing drivers can be abused to achieve persistence or elevate capabilities, so monitoring this pattern helps catch non-administrative driver deployment attempts. It relies on Windows process creation telemetry, specifically the executable path ending with \pnputil.exe and matching command-line substrings.
references:
- https://learn.microsoft.com/en-us/windows-hardware/drivers/devtest/pnputil-command-syntax
- https://strontic.github.io/xcyclopedia/library/pnputil.exe-60EDC5E6BDBAEE441F2E3AEACD0340D2.html
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_lolbin_susp_driver_installed_by_pnputil.yml
author: Hai Vaknin @LuxNoBulIshit, Avihay eldad @aloneliassaf, Austin Songer @austinsonger, Huntrule Team
date: 2021-09-30
modified: 2022-10-09
tags:
- attack.privilege-escalation
- attack.persistence
- attack.t1547
logsource:
category: process_creation
product: windows
detection:
selection:
CommandLine|contains:
- -i
- /install
- -a
- /add-driver
- ".inf"
Image|endswith: \pnputil.exe
condition: selection
falsepositives:
- Pnputil.exe being used may be performed by a system administrator.
- Verify whether the user identity, user agent, and/or hostname should be making changes in your environment.
- Pnputil.exe being executed from unfamiliar users should be investigated. If known behavior is causing false positives, it can be exempted from the rule.
level: medium
license: DRL-1.1
related:
- id: a2ea3ae7-d3d0-40a0-a55c-25a45c87cac1
type: derived