Potential Kernel Module or Driver Load/Install
Detects process creations (EventID 4688) where the command line contains keywords indicative of loading or installing kernel modules or drivers. This activity can be associated with privilege escalation or persistence techniques used by adversaries.
Microsoft Sentinel (KQL)

