Technique.View on attack.mitre.org
Adversaries may attempt to enumerate local device drivers on a victim host. Information about device drivers may highlight various insights that shape follow-on behaviors, such as the function/purpose of the host, present security tools (i.e. Security Software Discovery) or other defenses (e.g., Virtualization/Sandbox Evasion), as well as potential exploitable vulnerabilities (e.g., Exploitation for Privilege Escalation).
Many OS utilities may provide information about local device drivers, such as `driverquery.exe` and the `EnumDeviceDrivers()` API function on Windows. Information about device drivers (as well as associated services, i.e., System Service Discovery) may also be available in the Registry.
On Linux/macOS, device drivers (in the form of kernel modules) may be visible within `/dev` or using utilities such as `lsmod` and `modinfo`.
Rules on DetectionCode tagged with T1652.
None recorded.
| Used by | Procedure example |
|---|---|
| GroupMedusa Group | Medusa Group has queried drivers on the victim device through the command `driverquery`. |
| Used by | Procedure example |
|---|---|
| MalwareHOPLIGHT | HOPLIGHT can enumerate device drivers located in the registry at `HKLM\Software\WBEM\WDM`. |
| MalwareINC Ransomware | INC Ransomware can verify the presence of specific drivers on compromised hosts including Microsoft Print to PDF and Microsoft XPS Document Writer. |
| MalwareRemsec | Remsec has a plugin to detect active drivers of some security products. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.