InstalledDrivers collector Published on Aug 26, 2026
Print
Copy page Copy as Markdown for LLMs View as Markdown View the page as plain text
Open in ChatGPT Ask ChatGPT about this page Open in Claude Ask Claude about this page Prev Next The InstalledDrivers collector shows details about drivers installed on managed devices.
Collector output
Field
Type
Description
displayname
String
The display name for the driver.
description
String
A description for the driver.
last_modified_date
Timestamp
A date-time value indicating when the driver was last modified.
name
String
A short name that uniquely identifies the driver.
servicetype
String
The type of service provided to calling processes.
startmode
String
The driver start-up mode.
Boot — the driver is started by the operating system loader.
System — the driver is started by the operating system.
Automatic — the driver starts automatically at system startup.
Manual — the driver starts by the service control manager. The service control manager also allows to manually start the driver.
Disabled — the driver can no longer be started.
state
String
The current state of the driver.
path
String
The fully qualified path to the driver file.
Example: Show drivers which are disabled on devices.
InstalledDrivers where InstalledDrivers state equals "disabled"
Was this article helpful?
Yes No
Related articles
Endpoint Detection and Response (EDR) > Endpoint Detection and Response Product Guide > Collecting device data for real-time search > Built-in collectors
Endpoint Detection and Response with Forensics (EDRF) > Investigate potential threats with EDRF > Conduct searches > Search real-time data of endpoints for investigation and threat hunting > Collecting device data for real-time search > Built-in collectors
Endpoint Detection and Response (EDR) > Endpoint Detection and Response Product Guide > Collecting device data for real-time search > Built-in collectors