logo

You’re Driving Me Crazy: Analysing and Detecting BYOVD

ID: 63214db9-223c-516c-a165-268a5c06035d

STIX ID: report--63214db9-223c-516c-a165-268a5c06035d

Feed Name: Ransomware ISAC Blog

Threat Score
78/100

Date Published: 2026-04-03

Date Updated: 2026-08-21

Author: [email protected] (Alex Necula)

...
...

This report documents Bring Your Own Vulnerable Driver (BYOVD) attacks against Windows: it details vulnerability research on the WatchDog v1.1.100 and eb drivers, demonstrates how adversaries (including ransomware groups like Qilin and RansomHub) use signed but vulnerable drivers to terminate PPL-protected EDR processes, and provides operational detection (KQL), incident-response playbooks, and hardening recommendations (WDAC, HVCI, least privilege).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.