You’re Driving Me Crazy: Analysing and Detecting BYOVD
ID: 63214db9-223c-516c-a165-268a5c06035d
STIX ID: report--63214db9-223c-516c-a165-268a5c06035d
Feed Name: Ransomware ISAC Blog
Threat Score
This report documents Bring Your Own Vulnerable Driver (BYOVD) attacks against Windows: it details vulnerability research on the WatchDog v1.1.100 and eb drivers, demonstrates how adversaries (including ransomware groups like Qilin and RansomHub) use signed but vulnerable drivers to terminate PPL-protected EDR processes, and provides operational detection (KQL), incident-response playbooks, and hardening recommendations (WDAC, HVCI, least privilege).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
