PUA - Kernel Driver Utility (KDU) Execution — Detection Rule

Detects execution of the Kernel Driver Utility (KDU) tool. KDU can be used to bypass driver signature enforcement and load unsigned or malicious drivers into the Windows kernel. Potentially allowing for privilege escalation, persistence, or evasion of security controls.

Read the full analysis on IntelFusions