Detect Potential Driver/Kernel Module Installation
This rule detects the creation of new processes (Event ID 4688) where the command line contains keywords indicative of driver or kernel module installation or loading. It looks for combinations of terms like 'driver', 'kernel', 'sys' along with 'install' or 'load'. This activity can be a sign of rootkit installation or other malicious kernel-level modifications.
Microsoft Sentinel (KQL)

