drivers‑signature Audit

Prev Next

Collects loaded driver structures by scanning the memory of host endpoints.

This audit was formerly known as the w32drivers-signature audit.

Supported Platforms

Windows only

Memory-related audits are now supported for host endpoints running the following Windows operating system versions.

  • Windows XP (32-bit)

  • Windows 7 (32-bit & 64-bit)

  • Windows Server 2012 R2 (64-bit)

  • Windows Server 2016 (64-bit)

  • Windows 8.1 (32-bit)

  • Windows 10 TS1 - RS5 (64-bit)

Input Parameters

The following input parameters are available for this audit.

memory file

Details

Values

Description

Platform

Windows

Windows environments

Format

FilePath

Valid values are a full file path and file name.

Required?

no

This parameter is not required.

Repeatable?

no

This parameter can be specified only once per audit request. It cannot be repeated.

Valid Values

Specify the full path and file name of the file that represents the host endpoint's physical memory.

enumerate imports Parameter

Details

Values

Description

Platform

Windows

Windows environments

Format

Bool

Valid values are Boolean values.

Required?

no

This parameter is not required.

Repeatable?

no

This parameter can be specified only once per audit request. It cannot be repeated.

Valid Values

Use Boolean values to indicate whether to enumerate imports of all loaded modules for a given driver.

enumerate exports

Details

Values

Description

Platform

Windows

Windows environments

Format

Bool

Valid values are Boolean values.

Required?

no

This parameter is not required.

Repeatable?

no

This parameter can be specified only once per audit request. It cannot be repeated.

Valid Values

Use Boolean values to indicate whether to enumerate exports of all loaded modules for a given driver.

strings

Details

Values

Description

Platform

Windows

Windows environments

Format

Bool

Valid values are Boolean values.

Required?

no

This parameter is not required.

Repeatable?

no

This parameter can be specified only once per audit request. It cannot be repeated.

Valid Values

Use Boolean values to indicate whether to parse a specified driver for strings.

shortest matched string

Details

Values

Description

Platform

Windows

Windows environments

Format

Numeric

Valid values are numeric.

Required?

no

This parameter is not required.

Repeatable?

no

This parameter can be specified only once per audit request. It cannot be repeated.

Valid Values

Specify the minimum recognized string length.

Preserve Times

Details

Values

Description

Platform

Windows

Windows environments

Format

Bool

Valid values are Boolean values.

Required?

no

This parameter is not required.

Repeatable?

no

This parameter can be specified only once per audit request. It cannot be repeated.

Valid Values

Use Boolean values to indicate whether the last access times for audited files should be manually reset.

MD5

Details

Values

Description

Platform

Windows

Windows environments

Format

Bool

Valid values are Boolean values.

Required?

no

This parameter is not required.

Repeatable?

no

This parameter can be specified only once per audit request. It cannot be repeated.

Valid Values

Use Boolean values to indicate whether an MD5 hash should be computed for each returned file.

SHA1

Details

Values

Description

Platform

Windows

Windows environments

Format

Bool

Valid values are Boolean values.

Required?

no

This parameter is not required.

Repeatable?

no

This parameter can be specified only once per audit request. It cannot be repeated.

Valid Values

Use Boolean values to indicate whether an SHA1 hash should be computed for each returned file.

SHA256

Details

Values

Description

Platform

Windows

Windows environments

Format

Bool

Valid values are Boolean values.

Required?

no

This parameter is not required.

Repeatable?

no

This parameter can be specified only once per audit request. It cannot be repeated.

Valid Values

Use Boolean values to indicate whether an SHA256 hash should be computed for each returned file.

Verify Digital Signatures

Details

Values

Description

Platform

Windows

Windows environments

Format

Bool

Valid values are Boolean values.

Required?

no

This parameter is not required.

Repeatable?

no

This parameter can be specified only once per audit request. It cannot be repeated.

Valid Values

Use Boolean values to indicate whether the audit should verify that the loaded drivers are digitally signed. This operation cannot be performed on a memory image.

raw mode

Details

Values

Description

Platform

Windows

Windows environments

Format

Bool

Valid values are Boolean values.

Required?

no

This parameter is not required.

Repeatable?

no

This parameter can be specified only once per audit request. It cannot be repeated.

Valid Values

Use Boolean values to indicate whether to open files for hashing in raw mode.

Prevent Hibernation

Details

Values

Description

Platform

Windows

Windows environments

Format

Bool

Valid values are Boolean values.

Required?

no

This parameter is not required.

Repeatable?

no

This parameter can be specified only once per audit request. It cannot be repeated.

Valid Values

Use Boolean values to indicate whether to prevent the host endpoint from entering hibernation while this audit is executed.