Device Driver Discovery

T1652

Technique.View on attack.mitre.org

About this technique

Adversaries may attempt to enumerate local device drivers on a victim host. Information about device drivers may highlight various insights that shape follow-on behaviors, such as the function/purpose of the host, present security tools (i.e. Security Software Discovery) or other defenses (e.g., Virtualization/Sandbox Evasion), as well as potential exploitable vulnerabilities (e.g., Exploitation for Privilege Escalation).

Many OS utilities may provide information about local device drivers, such as `driverquery.exe` and the `EnumDeviceDrivers()` API function on Windows. Information about device drivers (as well as associated services, i.e., System Service Discovery) may also be available in the Registry.

On Linux/macOS, device drivers (in the form of kernel modules) may be visible within `/dev` or using utilities such as `lsmod` and `modinfo`.

Detection rules0

Rules on DetectionCode tagged with T1652.

Sigma0

No Sigma rules are mapped to this technique yet.

Splunk0

No Splunk rules are mapped to this technique yet.

Groups1

Software3

Campaigns0

None recorded.

Procedure examples4

Groups1

Used byProcedure example
GroupMedusa Group

Medusa Group has queried drivers on the victim device through the command `driverquery`.

Software3

Used byProcedure example
MalwareHOPLIGHT

HOPLIGHT can enumerate device drivers located in the registry at `HKLM\Software\WBEM\WDM`.

MalwareINC Ransomware

INC Ransomware can verify the presence of specific drivers on compromised hosts including Microsoft Print to PDF and Microsoft XPS Document Writer.

MalwareRemsec

Remsec has a plugin to detect active drivers of some security products.

References6

  1. Linux Kernel Programming Open source
    Pomerantz, O., Salzman, P.. (2003, April 4). The Linux Kernel Module Programming Guide. Retrieved April 6, 2018.
  2. Microsoft Driverquery Open source
    Microsoft. (n.d.). driverquery. Retrieved March 28, 2023.
  3. Microsoft EnumDeviceDrivers Open source
    Microsoft. (2021, October 12). EnumDeviceDrivers function (psapi.h). Retrieved March 28, 2023.
  4. Microsoft Registry Drivers Open source
    Microsoft. (2021, December 14). Registry Trees for Devices and Drivers. Retrieved March 28, 2023.
  5. lsmod man Open source
    Kerrisk, M. (2022, December 18). lsmod(8) — Linux manual page. Retrieved March 28, 2023.
  6. modinfo man Open source
    Russell, R. (n.d.). modinfo(8) - Linux man page. Retrieved March 28, 2023.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.