Sysmon Event ID 6: Driver loaded
- Event ID
- 6
- Channel
- Microsoft-Windows-Sysmon/Operational
- Provider
- Microsoft-Windows-Sysmon
- Log file
- Microsoft-Windows-Sysmon%4Operational.evtx
- Category
- System
- Default logging
- Needs configuration
What event 6 means
Sysmon event 6 records a driver loading into the kernel, with its path (ImageLoaded), hashes and signature information (Signed, Signature, SignatureStatus). The signature check runs asynchronously, so the event can also tell you if the file was already gone after loading.
Driver loads are rare after boot, which makes them good hunting ground. The main threat today is "bring your own vulnerable driver": attackers load a legitimately signed but exploitable driver to kill EDR processes or gain kernel access. Rootkits and some ransomware families also install drivers.
Most configurations exclude drivers signed by Microsoft and log everything else.
When it is logged
Sysmon installed; filter with <DriverLoad> rules (commonly excluding signatures containing Microsoft or Windows).
Key fields
| Field | What it tells you |
|---|---|
| UtcTime | Load time. |
| ImageLoaded | Path of the driver file. Drivers outside C:\Windows\System32\drivers deserve a look. |
| Hashes | Driver hashes. Compare against lists of known vulnerable drivers (e.g. the LOLDrivers project). |
| Signed | true or false: whether the driver is signed. |
| Signature | Signer name. Look for unexpected vendors or revoked gaming or hardware-utility certificates. |
| SignatureStatus | Result of signature validation, e.g. Valid, or a status showing an expired or revoked certificate. |
Common benign sources
- Hardware and peripheral drivers after device installation or Windows Update.
- Security, backup, virtualization and VPN products loading their filter drivers.
What attackers do that produces it
- Loading a known vulnerable signed driver (BYOVD) from a temp or user folder, followed by security products stopping.
- Unsigned or oddly signed drivers loaded shortly after a new service is created (System 7045).
Investigation tips
- Check hashes against known vulnerable driver lists and threat intelligence.
- Look for the service that loaded the driver in System 7045 or Security 4697.
- Check whether EDR or antivirus processes stopped right after the load (Sysmon 5, System 7036).
MITRE ATT&CK techniques
MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.
Sigma rules for this event
10 SigmaHQ detection rules (release r2026-07-01) target this event.
- High · 7
- Medium · 2
- Low · 1
- HighDriver Load From A Temporary DirectoryRule by Florian Roth (Nextron Systems), SigmaHQ, DRL 1.1
- HighMalicious Driver LoadRule by Nasreddine Bencherchali (Nextron Systems), SigmaHQ, DRL 1.1
- HighPUA - Process Hacker Driver LoadRule by Florian Roth (Nextron Systems), SigmaHQ, DRL 1.1
- HighVulnerable Driver LoadRule by Nasreddine Bencherchali (Nextron Systems), SigmaHQ, DRL 1.1
- HighVulnerable HackSys Extreme Vulnerable Driver LoadRule by Nasreddine Bencherchali (Nextron Systems), SigmaHQ, DRL 1.1
- HighVulnerable WinRing0 Driver LoadRule by Florian Roth (Nextron Systems), SigmaHQ, DRL 1.1
- HighWinDivert Driver LoadRule by Florian Roth (Nextron Systems), SigmaHQ, DRL 1.1
- MediumMalicious Driver Load By NameRule by Nasreddine Bencherchali (Nextron Systems), SigmaHQ, DRL 1.1
- MediumPUA - System Informer Driver LoadRule by Florian Roth (Nextron Systems), SigmaHQ, DRL 1.1
- LowVulnerable Driver Load By NameRule by Nasreddine Bencherchali (Nextron Systems), SigmaHQ, DRL 1.1
Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.
Run these rules on your logs
Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.