logo

You’re Driving Me Crazy: Analysing and Detecting BYOVD

ID: 6c982428-08a2-5359-856e-06c1ce6438d8

STIX ID: report--6c982428-08a2-5359-856e-06c1ce6438d8

Feed Name: Ransomware ISAC Blog

Threat Score
80/100

Date Published: 2026-04-03

Date Updated: 2026-07-28

Author: [email protected] (Alex Necula)

...
...

Bring Your Own Vulnerable Driver (BYOVD) attacks exploit legitimately signed but flawed Windows kernel drivers to perform kernel-level actions—most critically terminating Protected Process Light (PPL) EDR/antivirus processes—bypassing user-mode protections. This report analyzes two drivers (WatchDog v1.1.100 and eb.sys), documents real-world ransomware toolchains and underground marketplaces selling EDR-killers, and provides a behavioral detection methodology (including KQL), incident response playbook, and hardening recommendations (WDAC, HVCI, driver inventory) to mitigate these high-impact attacks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.