You’re Driving Me Crazy: Analysing and Detecting BYOVD
ID: 6c982428-08a2-5359-856e-06c1ce6438d8
STIX ID: report--6c982428-08a2-5359-856e-06c1ce6438d8
Feed Name: Ransomware ISAC Blog
Bring Your Own Vulnerable Driver (BYOVD) attacks exploit legitimately signed but flawed Windows kernel drivers to perform kernel-level actions—most critically terminating Protected Process Light (PPL) EDR/antivirus processes—bypassing user-mode protections. This report analyzes two drivers (WatchDog v1.1.100 and eb.sys), documents real-world ransomware toolchains and underground marketplaces selling EDR-killers, and provides a behavioral detection methodology (including KQL), incident response playbook, and hardening recommendations (WDAC, HVCI, driver inventory) to mitigate these high-impact attacks.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
