The feature that stops BYOVD (bring your own vulnerable driver)
ID: 2929c318-6407-515d-91c7-95c5595c9f29
STIX ID: report--2929c318-6407-515d-91c7-95c5595c9f29
Feed Name: Expel Blog
This report explains how BYOVD (Bring Your Own Vulnerable Driver) attacks exploit legitimately signed but vulnerable drivers to achieve kernel-level compromise, demonstrates the limitations of driver blocklists (like Microsoft’s Vulnerable Driver Blocklist), and recommends a deny-by-default strategy using Windows Defender Application Control (WDAC) combined with Hypervisor‑Protected Code Integrity (HVCI), Active Directory/GPO deployment patterns, and complementary controls (VBS, disabling legacy cross-signing, ASR rules, community blocklists) to mitigate the threat.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
