A Valid Microsoft Signature Does Not Mean a Driver Is Safe by Lucie Cardiet
ID: 27dc3e68-f6e3-5a27-8034-a178f9fe1d05
STIX ID: report--27dc3e68-f6e3-5a27-8034-a178f9fe1d05
Feed Name: Vectra AI Blog
**Executive Summary:** The report describes BYOVD campaigns where ransomware operators (tracked as Hackledorb/DragonForce and observed via the GentleKiller framework) loaded legitimate, signed kernel drivers — including one without a CVE at time of attack — to disable security tools, exploiting a timing gap between vulnerability discovery/CVE assignment and Microsoft’s vulnerable-driver blocklist; defenders can detect pre-kill activity by monitoring Event ID 7045 and mitigate structurally via Memory Integrity (HVCI).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
