Malicious Known Vulnerable Driver Load for BYOVD Attack

PremiumReviewedSigma · High · v1
Product
windows
Category
driver_load
Author
HuntRule
Published
2026-09-09
Updated
2026-09-09

ATT&CK techniques

Persistence → Priv Esc
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Defense Evasion

  6. Cred Access

  7. Discovery

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule detects loading of known vulnerable kernel drivers such as viragt64.sys dbutil_2_3.sys zamguard64.sys RtCore64.sys gdrv.sys and empntdrv.sys which adversaries abuse in bring your own vulnerable driver attacks to disable security tooling and gain kernel level execution. Presence of these driver filenames loading on an endpoint is a strong indicator of privilege escalation or defense evasion activity.

Related detections9 linkedT1068 — drag to rearrange
Malicious Qilin EDR Killer BYOVD Driver Load
Malicious Bring-Your-Own-Vulnerable-Driver Load for EDR Killing
Suspicious Qilin EDR Killer BYOVD Service Installation via sc
Suspicious Masqueraded Zemana Driver Written to Disk via updatedrv (via file_event)
Suspicious Service Registration Loading Vulnerable Driver
Malicious Vulnerable Driver Load for BYOVD Defense Evasion (via image_load)
Windows Malicious Driver Load Identified by Known Bad Driver File Names
Windows Driver Load of Known Vulnerable Drivers by File Name
Windows Malicious Driver Load by Known Hashes
Malicious Known Vulnerable Driver Load for BYOVD Attack
Pivot detection · T1068 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.