logo

The feature that stops BYOVD (bring your own vulnerable driver)

ID: 2929c318-6407-515d-91c7-95c5595c9f29

STIX ID: report--2929c318-6407-515d-91c7-95c5595c9f29

Feed Name: Expel Blog

Threat Score
70/100

Date Published: 2026-07-23

Date Updated: 2026-07-24

...
...

This report explains how BYOVD (Bring Your Own Vulnerable Driver) attacks exploit legitimately signed but vulnerable drivers to achieve kernel-level compromise, demonstrates the limitations of driver blocklists (like Microsoft’s Vulnerable Driver Blocklist), and recommends a deny-by-default strategy using Windows Defender Application Control (WDAC) combined with Hypervisor‑Protected Code Integrity (HVCI), Active Directory/GPO deployment patterns, and complementary controls (VBS, disabling legacy cross-signing, ASR rules, community blocklists) to mitigate the threat.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.