logo

Blocking BYOVD Techniques to Prevent AV/EDR/XDR Bypasses

ID: 201bc0c8-2810-508e-b75e-93a436b556e8

STIX ID: report--201bc0c8-2810-508e-b75e-93a436b556e8

Feed Name: Halcyon Blog

Threat Score
75/100

Date Published: 2026-03-02

Date Updated: 2026-04-28

...
...

The report explains how threat actors leverage legitimately signed but vulnerable Windows kernel drivers (Bring Your Own Vulnerable Driver — BYOVD) — notably the 'Terminator' tool sold on cybercrime forums — to obtain kernel-level privileges and bypass AV/EDR solutions; it cites historical usage by Lazarus and ransomware groups (Cuba, D0nut) and advises enabling Microsoft's vulnerable driver blocklist, WDAC, HVCI or S mode and rebooting to mitigate these attacks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.