Potential Rootkit Installation via Administrative Utilities

This rule detects the usage of standard Windows system administration utilities (infinstall.exe, devcon.exe, pnputil.exe, sc.exe) when the command line arguments include keywords commonly associated with driver loading or kernel-level operations, which may indicate the installation of a rootkit or malicious driver.