Malicious Vulnerable Driver Load by GentleKiller BYOVD EDR Killer

PremiumReviewedSigma · High · v1
Product
windows
Category
driver_load
Author
HuntRule
Published
2026-09-23
Updated
2026-09-23

ATT&CK techniques

Persistence → Priv Esc
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Defense Evasion

  6. Cred Access

  7. Discovery

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule detects loading of known vulnerable or malicious kernel drivers abused by the GentleKiller BYOVD framework to disable endpoint security. The Gentlemen intrusion set uses these signed drivers to gain kernel access and terminate hundreds of protection processes. Detecting these specific driver names is important because a successful load precedes mass tampering with security tooling and credential theft.

Related detections9 linkedT1685 — drag to rearrange
Malicious Known Vulnerable Driver Load for BYOVD Attack
Suspicious Service binPath Hijack Followed by System Reboot
Malicious Qilin EDR Killer BYOVD Driver Load
Malicious Bring-Your-Own-Vulnerable-Driver Load for EDR Killing
Suspicious Qilin EDR Killer BYOVD Service Installation via sc
Suspicious Masqueraded Zemana Driver Written to Disk via updatedrv (via file_event)
Suspicious Service Registration Loading Vulnerable Driver
Malicious Vulnerable Driver Load for BYOVD Defense Evasion (via image_load)
Windows Malicious Driver Load Identified by Known Bad Driver File Names
Malicious Vulnerable Driver Load by GentleKiller BYOVD EDR Killer
Pivot detection · T1685 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.