logo

54 EDR Killers Use BYOVD to Exploit 34 Signed Vulnerable Drivers and Disable Security

ID: b64d75ff-121c-5857-ab2a-c8e848cede83

STIX ID: report--b64d75ff-121c-5857-ab2a-c8e848cede83

Feed Name: The Hacker News

Threat Score
75/100

Date Published: 2026-03-19

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

ESET analysis reveals that many EDR-killer tools—specialized utilities used to disable endpoint detection and response before ransomware deployment—rely heavily on BYOVD (bring your own vulnerable driver) techniques, abusing dozens of legitimate signed drivers to achieve kernel-level access and neutralize security products; the report outlines developer/actor types, tool categories (script-based, anti-rootkit, driverless), and urges layered defenses and driver-blocking to mitigate the threat.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.