logo

CrowdStrike Falcon Prevents Multiple Vulnerable Driver Attacks in Real-World Intrusion

ID: 2a8e3b19-578a-540c-ae07-117b92ea64dd

STIX ID: report--2a8e3b19-578a-540c-ae07-117b92ea64dd

Feed Name: Crowdstrike Blog

Threat Score
70/100

Date Published: 2024-12-02

Date Updated: 2026-04-27

Author: Matt Weiner - Ioan-Cristian Iacob

...
...

CrowdStrike describes a marked increase in BYOVD (bring your own vulnerable driver) attacks used to bypass endpoint detection by loading legitimate but vulnerable kernel drivers. The report details a September 2024 intrusion where attackers brought six vulnerable drivers (all detected or blocked by Falcon), explains BYOVD mechanics and attacker objectives (kernel memory access, disabling Driver Signature Enforcement, mapping unsigned drivers, hiding artifacts), and classifies abused drivers to support detection and mitigation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.