This analysis covers the BYOVD (Bring Your Own Vulnerable Driver) technique used by 'EDR killers' – 54 unique variants abusing 35 known vulnerable signed drivers to disable security tools, escalate privileges, and deploy payloads like ransomware undetected.
Windows environments where vulnerable signed drivers can be loaded.
Abusing trusted signed drivers neutralizes EDR, removing a primary detection/response layer before ransomware deployment.
- Enable Microsoft's vulnerable-driver blocklist with WDAC/HVCI.
- Monitor driver loads (Sysmon EID 6) for known-vulnerable drivers.
- Implement driver allow-listing and least privilege.
- Alert on security-service tampering/stops.
Key Technical Findings
BYOVD technique used by EDR-killer tooling (54 variants, 35 vulnerable drivers).
Windows hosts that allow loading of vulnerable signed drivers.
Social engineering or software-vulnerability exploitation.
Execution via the loaded malicious/vulnerable driver (T1203).
Driver-based footholds for sustained access.
Kernel-level access via driver manipulation.
Disabling EDR/security services via trusted signed drivers.
Not specified in the source material.
Not specified in the source material.
C2 over application-layer protocols (T1071).
High – security-tool neutralization enabling ransomware.
Technical Background
BYOVD abuses the trust EDR places in signed drivers: attackers load a legitimate-but-vulnerable (or malicious) kernel driver, exploit it for arbitrary code execution or to disable security services, and escalate to kernel privileges. With EDR neutralized, payloads like ransomware run undetected.
Because integrity checks pass for signed drivers, defense shifts to the vulnerable-driver blocklist/HVCI, driver-load monitoring (Sysmon EID 6), allow-listing, and alerting on security-service tampering.
Attack Chain Analysis
-
Initial Access
ActivityGain access via social engineering or exploitation.
EvidenceAccess precursors.
TelemetryEDR, email/web logs.
Detection opportunityCorrelate access with driver activity.
-
Execution
ActivityLoad and exploit a vulnerable/malicious driver (T1203).
EvidenceSuspicious driver load/service creation.
TelemetrySysmon EID 6, Security 7045.
Detection opportunityAudit driver loads against the blocklist.
-
Defense Evasion
ActivityDisable EDR/security services.
EvidenceSecurity services stopped/tampered.
TelemetryService logs, EDR health.
Detection opportunityAlert on security-tool tampering.
-
Privilege Escalation
ActivityGain kernel privileges via the driver.
EvidenceKernel-level anomalies.
TelemetryEDR, Sysmon.
Detection opportunityDetect driver-based escalation.
-
Impact
ActivityDeploy ransomware/payloads.
EvidenceMass encryption.
TelemetryEDR/FIM.
Detection opportunityAlert on rapid mass file changes.
Deep Technical Behavior Analysis
The defining behavior is loading a trusted-but-vulnerable driver to reach the kernel and disable defenses. The strongest controls are the Microsoft vulnerable-driver blocklist, HVCI, and Sysmon EID 6 monitoring, since signature-based trust is exactly what the technique abuses.
The specific driver list and tooling indicators are not fully specified in the source material and require validation.
Indicators of Compromise
Indicators of Behavior
Behavioral indicators to hunt for even when atomic IoCs are limited (Potential — validate against your baseline).
| Behavioral Indicator | Description | Data Source | Confidence |
|---|---|---|---|
| Anomalous PowerShell execution | Encoded/obfuscated commands, download cradles, or unusual parent-child process lineage. | Sysmon EID 1, PowerShell 4104 | Potential |
| Suspicious child process lineage | Office or web/service processes spawning script hosts or shells. | Sysmon EID 1, EDR | Potential |
| Security log clearing | Event log cleared or audit policy changed to hinder visibility. | Windows Security 1102, 4719 | Potential |
| New service / scheduled task creation | Unexpected persistence via services or tasks. | Security 7045, 4698; Sysmon | Potential |
| Beaconing to rare destinations | Periodic outbound connections to newly-seen domains/IPs or direct-IP C2. | Proxy, firewall, DNS logs | Potential |
| Unusual DNS queries | High-entropy or rare domains; possible tunneling. | DNS resolver logs | Potential |
Detection Engineering Guidance
Defensive detection logic (Potential — tune to your environment). No exploit code is included; logic is for hunting and alerting only.
pseudo: periodic outbound (low jitter) to newly-seen domain/IP
with small uniform payloads => alert(level=medium)
Recommended Log Sources
| Platform | Log Source | What to Look For | Priority |
|---|---|---|---|
| Windows | Security Event Log | Logon (4624/4625), service (7045), task (4698), log clear (1102) | High |
| Windows | Sysmon | Process creation (1), network (3), image load (7), LSASS access (10) | High |
| Windows | PowerShell Operational | Script block logging (4104), module logging | High |
| Endpoint | EDR / Defender telemetry | Process tree, persistence, tamper attempts | High |
| Network | DNS resolver logs | Rare/high-entropy domains, tunneling | Medium |
| Network | Proxy / firewall logs | Beaconing, direct-IP C2, exfil volume | High |
MITRE ATT&CK Mapping
| Tactic | Technique ID | Technique Name | Relevance | Detection Opportunity | Confidence |
|---|---|---|---|---|---|
| Execution | T1203 | Exploitation for Client Execution | Exploitation of client applications to execute malicious code. | Monitoring application logs for unusual behavior or error messages. | Reported |
| Command and Control | T1071 | Application Layer Protocol | Use of application layer protocols for C2 communication. | Inspecting network traffic for anomalies in application layer protocols. | Reported |
Incident Response Guidance
- Validate exposure and confirm whether the issue applies to your environment.
- Preserve evidence (memory, disk, relevant logs) before remediation.
- Isolate affected hosts/accounts if compromise is suspected.
- Collect volatile data and review the log sources listed above.
- Hunt for the indicators of behavior and any related atomic indicators.
- Rotate potentially exposed credentials, keys, and session tokens.
- Remove persistence (tasks, services, keys, web shells, cron, OAuth grants).
- Patch affected systems; reimage where integrity cannot be assured.
- Run post-remediation validation and a BAS/security-validation retest.
Remediation and Hardening
- Patch affected systems and reduce internet-exposed services.
- Enforce MFA and least-privilege for privileged and remote access.
- Improve endpoint telemetry (Sysmon/EDR) and PowerShell logging.
- Restrict script execution and constrain LOLBins where feasible.
- Monitor persistence locations and disable unnecessary services.
- Segment critical assets and review privileged accounts.
- Rotate secrets and remove credentials from configuration files.
- Tune SIEM/EDR detections, then validate controls after changes.
Business Risk
- Service disruption: degraded or unavailable systems during compromise or recovery.
- Data exposure: risk to sensitive, regulated, or customer data depending on scope.
- Regulatory exposure: potential breach-notification and compliance obligations.
- Financial impact: incident response, downtime, and potential extortion costs.
- Brand and trust impact: reputational damage with customers and partners.
- Operational continuity: ransomware can halt critical business processes until restored.
Executive Takeaway
What leadership needs to know: Abusing trusted signed drivers neutralizes EDR, removing a primary detection/response layer before ransomware deployment. Current assessed risk: High.
Prioritise: patching/exposure reduction, identity hardening (MFA, least privilege), and detection coverage for the techniques above.
Validate after remediation: re-test controls with breach & attack simulation to confirm the relevant techniques are now prevented or detected.
Validating Your Defenses with Valitrix
The Valitrix Breach and Attack Simulation (BAS) platform offers organizations a unique opportunity to validate their defenses against threats leveraging the BYOVD technique. By simulating real-world attack scenarios mapped to the MITRE ATT&CK framework, Valitrix enables security teams to assess their detection capabilities against known vulnerabilities in signed drivers. This proactive validation helps organizations understand their security posture and identify gaps that need addressing.
Through continuous testing and validation of security controls, Valitrix allows organizations to refine their defenses against evolving threats. By emulating specific techniques used by EDR killers, Valitrix ensures that security measures remain effective over time, ultimately reducing the risk of successful attacks exploiting vulnerable drivers.
Key Takeaways
- The BYOVD technique is a significant threat used by EDR killers to bypass security measures.
- A total of 54 identified EDR killers exploit 35 vulnerable drivers.
- Understanding the relationship between drivers and EDR systems is critical for effective security strategies.
- Implementing continuous monitoring and threat intelligence is vital for early detection.
- Regular updates and vulnerability management can mitigate risks associated with known vulnerabilities.
Frequently Asked Questions
What is the BYOVD technique?
The BYOVD technique involves attackers exploiting vulnerable drivers on a system to bypass security measures effectively.
How do EDR killers utilize BYOVD?
EDR killers leverage BYOVD by exploiting signed vulnerable drivers, allowing them to disable endpoint security and execute malicious payloads without detection.
What are common signs of a BYOVD attack?
Signs may include unexpected driver updates, unusual system behavior, and disabled security software; continuous monitoring is essential for detecting these anomalies.



