Suspected Rootkit Installation via Administrative Tools
Detects the use of legitimate administrative tools (regsvcs.exe, infinstall.exe, devcon.exe) being executed with command-line arguments indicative of driver or kernel-level installations (e.g., 'kernel', 'ring0', 'driver install'). This behavior is commonly associated with the installation of rootkits or the execution of Bring Your Own Vulnerable Driver (BYOVD) attacks to gain kernel-mode privileges.
Microsoft Sentinel (KQL)

