DEF CON 34 – Hernando/Martinez – Driver install triggered by PnP auto-install from removable media
This rule detects the loading of a driver by system utilities (drvinst.exe, pnputil.exe, setupapi.dll, or System process) shortly after a PnP (Plug and Play) device connection event. It specifically flags instances where the driver file is located in suspicious directories (Windows/Temp, Users/Public, AppData/Local/Temp) or the file does not have a .sys extension, which are common indicators of malicious driver installation or BYOVD (Bring Your Own Vulnerable Driver) tactics.
Microsoft Sentinel (KQL)

