The BYOVD Epidemic: How Attackers Are Weaponizing Trusted Windows Drivers to Kill Security
ID: 36874e34-6e77-53b2-bd89-4f3e0a2a0f6c
STIX ID: report--36874e34-6e77-53b2-bd89-4f3e0a2a0f6c
Feed Name: security.com
This report outlines the rise of BYOVD (Bring Your Own Vulnerable Driver) as a dominant defense-evasion technique: attackers drop legitimately signed but vulnerable kernel drivers, exploit them to reach kernel mode, and then disable or blind AV/EDR products—an approach now commoditized in ransomware toolkits—while noting that traditional kernel hardening and signature-based defenses are often insufficient and advocating driver-agnostic behavioral detection of suspicious IOCTL interactions.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
