#KernelExploitation
54 EDR killers exploit 34 signed vulnerable drivers using BYOVD to gain kernel privileges and disable endpoint protections before encryption. Tools come from ransomware groups, POC forkers, and marketplace sellers. #KernelExploitation #EDRKiller
54 EDR Killers Use BYOVD to Exploit 34 Signed Vulnerable Drivers and Disable Security
A new analysis found 54 EDR killers abusing 34 vulnerable drivers via the bring your own vulnerable driver (BYOVD) technique to gain kernel privileges and disable endpoint protections before encryption. These tools are developed by closed ransomware groups, proof-of-concept forkers, and marketplace sellers and include examples such as DemoKiller, EDRSilencer, and...
www.hendryadrian.com
March 20, 2026 at 7:00 AM
2/14 Alternative Exploitation: Instead of the write-up's method, @chc4 suggests a type confusion attack by spraying sockets & incorrectly casting them to `vsock_sock` for kernel memory control. Tricky stuff! 🤯 #KernelExploitation #TypeConfusion #Security
May 2, 2025 at 6:32 AM
Code Execution Inside PID 0

Achieving kernel-level code execution in the System Idle Process by hooking power management routines in nt!PoIdle.

https://archie-osu.github.io/2025/04/13/powerhook.html

#KernelExploitation #WindowsInternals
April 26, 2025 at 5:30 AM