velociraptor
velociraptor copied to clipboard
Add Authenticode to Windows.Sys.Drivers/RunningDrivers
A very useful datapoint for running drivers is signing status. Consider adding Authenticode metadata for the binary in PathName
in the results of Windows.Sys.Drivers/RunningDrivers