Blocking BYOVD Techniques to Prevent AV/EDR/XDR Bypasses
ID: 201bc0c8-2810-508e-b75e-93a436b556e8
STIX ID: report--201bc0c8-2810-508e-b75e-93a436b556e8
Feed Name: Halcyon Blog
Threat Score
The report explains how threat actors leverage legitimately signed but vulnerable Windows kernel drivers (Bring Your Own Vulnerable Driver — BYOVD) — notably the 'Terminator' tool sold on cybercrime forums — to obtain kernel-level privileges and bypass AV/EDR solutions; it cites historical usage by Lazarus and ransomware groups (Cuba, D0nut) and advises enabling Microsoft's vulnerable driver blocklist, WDAC, HVCI or S mode and rebooting to mitigate these attacks.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
