logo

BYOVD: The Windows Kernel Internals That Let Attackers Kill Your EDR

ID: a75a2cca-b5c2-5ea7-a1fd-1e7f25e705c6

STIX ID: report--a75a2cca-b5c2-5ea7-a1fd-1e7f25e705c6

Feed Name: NoHackie

Threat Score
80/100

Date Published: 2026-02-12

Date Updated: 2026-04-19

...
...

In February 2026 Huntress investigated an intrusion where adversaries decoded and loaded an expired/revoked EnCase kernel driver (EnPortv.sys) to gain Ring 0 access and neutralize EDRs via Bring Your Own Vulnerable Driver (BYOVD) techniques; the report explains how Windows kernel architecture and driver-signing exceptions (no CRL checks, legacy acceptance) enable arbitrary kernel memory read/write, callback tampering, and PPL stripping, describes three vulnerability classes exploited in the wild, documents the attack chain and payload obfuscation, and recommends mitigations such as enabling HVCI/Memory Integrity, deploying WDAC/allowlisting, auditing drivers, monitoring driver installation, and enforcing credential hygiene.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.