Skip to content
Sysmon

Sysmon Event ID 6: Driver loaded

Driver loadedSysmon event 6 logs a kernel driver being loaded, with hashes and signature details. Rare and high-impact: watch for vulnerable or unsigned drivers.
6
Event ID
6
Channel
Microsoft-Windows-Sysmon/Operational
Provider
Microsoft-Windows-Sysmon
Log file
Microsoft-Windows-Sysmon%4Operational.evtx
Category
System
Default logging
Needs configuration

What event 6 means

Sysmon event 6 records a driver loading into the kernel, with its path (ImageLoaded), hashes and signature information (Signed, Signature, SignatureStatus). The signature check runs asynchronously, so the event can also tell you if the file was already gone after loading.

Driver loads are rare after boot, which makes them good hunting ground. The main threat today is "bring your own vulnerable driver": attackers load a legitimately signed but exploitable driver to kill EDR processes or gain kernel access. Rootkits and some ransomware families also install drivers.

Most configurations exclude drivers signed by Microsoft and log everything else.

When it is logged

Audit policy / configuration

Sysmon installed; filter with <DriverLoad> rules (commonly excluding signatures containing Microsoft or Windows).

Key fields

FieldWhat it tells you
UtcTimeLoad time.
ImageLoadedPath of the driver file. Drivers outside C:\Windows\System32\drivers deserve a look.
HashesDriver hashes. Compare against lists of known vulnerable drivers (e.g. the LOLDrivers project).
Signedtrue or false: whether the driver is signed.
SignatureSigner name. Look for unexpected vendors or revoked gaming or hardware-utility certificates.
SignatureStatusResult of signature validation, e.g. Valid, or a status showing an expired or revoked certificate.

Common benign sources

  • Hardware and peripheral drivers after device installation or Windows Update.
  • Security, backup, virtualization and VPN products loading their filter drivers.

What attackers do that produces it

  • Loading a known vulnerable signed driver (BYOVD) from a temp or user folder, followed by security products stopping.
  • Unsigned or oddly signed drivers loaded shortly after a new service is created (System 7045).

Investigation tips

  • Check hashes against known vulnerable driver lists and threat intelligence.
  • Look for the service that loaded the driver in System 7045 or Security 4697.
  • Check whether EDR or antivirus processes stopped right after the load (Sysmon 5, System 7036).

MITRE ATT&CK techniques

TechniqueTactics
T1014 RootkitStealth
T1068 Exploitation for Privilege EscalationPrivilege Escalation
T1543.003 Create or Modify System Process: Windows ServicePersistence, Privilege Escalation

MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.

Sigma rules for this event

10 SigmaHQ detection rules (release r2026-07-01) target this event.

  • High · 7
  • Medium · 2
  • Low · 1

Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.

Run these rules on your logs

Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.

Sources and further reading