• CommunityEnterprisePlans
  • Intel Exchange
    Intel ExchangeDetections
  • Resources
  • About
  • Leaderboard
Join CommunitySign In
    All Detections

    BYOVD gdrv.sys Vulnerable Driver File Detection

    avatar
    GlassDiceBearhttps://www.dicebear.comhttps://creativecommons.org/publicdomain/zero/1.0/„Glass” (https://www.dicebear.com) by „DiceBear”, licensed under „CC0 1.0” (https://creativecommons.org/publicdomain/zero/1.0/)
    Ibrahim Saud@tektrix
    •updated 21 days ago•0•0•1

    Detects the presence of the known vulnerable GIGABYTE driver (gdrv.sys) used in Bring Your Own Vulnerable Driver (BYOVD) attacks to bypass security controls and facilitate kernel-mode execution, as associated with Settra ransomware campaigns.

    YARA

    Tags

    T1068 - Exploitation for Privilege EscalationT1543.003 - Windows ServiceTA0003 - PersistenceFile EventFile CreationDriver LoadService CreatedWindowsWindows SysmonWindows Eventlog SystemSettra

    Found in

    • Settra Ransomware Variant Deploys MeshAgent RMMLast updated 21 days ago
    • Settra Ransomware Variant Deploys MeshAgent RMMLast updated 21 days ago
    • Settra Ransomware Variant Deploys MeshAgent RMMLast updated 21 days ago
    • Settra Ransomware Variant Deploys MeshAgent RMMLast updated 21 days ago
    • Settra Ransomware Variant Deploys MeshAgent RMMLast updated 21 days ago

    Community Inspired.
    AI Enhanced.
    Better Detections.

    Follow Us

    Company

    • About
    • Leaderboard

    Product

    • Community
    • Enterprise
    • Plans

    © 2026 Copyright. All Rights Reserved.

    Privacy PolicyTerms of Service

    Sign up to view this detection

    or

    Already have an account?