Skip to content

Latest commit

 

History

History
35 lines (28 loc) · 932 Bytes

FIRST-S00013.md

File metadata and controls

35 lines (28 loc) · 932 Bytes

Rules: First Seen Driver Load - Global

Description

{{device_hostname}} loaded new driver {{file_path}}.

Additional Details

Detail Value
Type First Seen
Category Execution
Apply Risk to Entities device_hostname
Signal Name Globally First Seen Driver Load: {{file_path}}
Summary Expression {{device_hostname}} loaded new driver {{file_path}}
Retention Window 7776000000
Baseline Window 1209600000
Baseline Type GLOBAL
Score/Severity Static: 2
Enabled by Default True
Prototype False
Tags _mitreAttackTactic:TA0002, _mitreAttackTechnique:T1014

Vendors and Products

Fields Used

Origin Field
Normalized Schema device_hostname
Normalized Schema file_path
Normalized Schema metadata_deviceEventId
Normalized Schema metadata_product
Normalized Schema metadata_vendor