Device Driver Discovery via driverquery, sc query, or PowerShell Driver Enumeration

Detects usage of common built-in tools (driverquery.exe, sc.exe) and PowerShell commands (Get-WindowsDriver, WMI queries for Win32_PnPSignedDriver or Win32_SystemDriver) used to enumerate installed system drivers. This is often part of reconnaissance to identify third-party drivers for BYOVD (Bring Your Own Vulnerable Driver) attacks.