avatar

0x 1337

@0x1337
0 followers0 downloads41 copies3 likes84 views

2 detections

This rule detects the loading of known vulnerable drivers on Windows systems by cross-referencing driver load events with a curated list of vulnerable drivers maintained by LOLDrivers.io. This technique, commonly referred to as 'Bring Your Own Vulnerable Driver' (BYOVD), is frequently used by adversaries to escalate privileges or perform kernel-mode exploitation.
avatar
0x 1337@0x1337
avatar
Detections.ai Community
2 months ago
40371
Detects the loading of known vulnerable drivers (BYOVD - Bring Your Own Vulnerable Driver) by cross-referencing Sysmon Event ID 6 (Driver Loaded) image hashes with the LOLDrivers.io project database. This technique is often used by adversaries to elevate privileges to kernel mode by exploiting vulnerabilities within signed, legitimate drivers.
avatar
0x 1337@0x1337
avatar
Detections.ai Community
2 months ago
1013