diff --git a/host-interaction/driver/install-driver.yml b/host-interaction/driver/install-driver.yml index 37bd16c6..3b15bb0d 100644 --- a/host-interaction/driver/install-driver.yml +++ b/host-interaction/driver/install-driver.yml @@ -11,10 +11,10 @@ rule: - Persistence::Create or Modify System Process::Windows Service [T1543.003] mbc: - Hardware::Install Driver [C0037] - examples: - - af60700383b75727f5256a0000c1476f:0x1127E references: - https://www.geoffchappell.com/studies/windows/km/ntoskrnl/api/ex/sysinfo/set.htm + examples: + - af60700383b75727f5256a0000c1476f:0x1127E features: - or: - api: ntdll.NtLoadDriver