Environment
- Microsoft Windows: All Supported Versions
Objective
Check to see what drivers are installed and their elevations to determine if one security software is detecting an event before another
Resolution
- Run CMD as Administrator
- FLTMC filters
- Each filter level driver will be listed with its elevation
- Lower elevations will see an event before higher elevations
- If a file is deleted by a lower level elevation driver then a higher elevation driver may not see that file
Related Content