Day 24 - LOLDRIVERS Malicious Driver Observed or Loaded
Featuring the awesome LOLDrivers project from @magicswordio
Anything they release is amazing and worth integrating in your detection/threat hunting rules, check them out!
github.com/SecurityAura...
Day 24 - LOLDRIVERS Malicious Driver Observed or Loaded
Featuring the awesome LOLDrivers project from @magicswordio
Anything they release is amazing and worth integrating in your detection/threat hunting rules, check them out!
github.com/SecurityAura...
→ LOLBAS: [lolbas-project.github.io](lolbas-project.github.io)
→ LOLDrivers: [loldrivers.io](www.loldrivers.io)
Detect abused tools & malicious drivers.
#LOLBins #LOLDrivers
→ LOLBAS: [lolbas-project.github.io](lolbas-project.github.io)
→ LOLDrivers: [loldrivers.io](www.loldrivers.io)
Detect abused tools & malicious drivers.
#LOLBins #LOLDrivers
academy.bluraven.io/blog/detecti...
#ThreatHunting #DetectionEngineering
academy.bluraven.io/blog/detecti...
#ThreatHunting #DetectionEngineering
This list enumerates 593 unique SHA256 Authentihashes for vulnerable drivers.
Of this list, only 56 are on the Microsoft recommended driver block rules.🤔
This list enumerates 593 unique SHA256 Authentihashes for vulnerable drivers.
Of this list, only 56 are on the Microsoft recommended driver block rules.🤔
https://github.com/magicsword-io/LOLDrivers
#cybersecurity
From: @screaminggoat […]
https://github.com/magicsword-io/LOLDrivers
#cybersecurity
From: @screaminggoat […]
📝 ## 🔍 Contexte
Le 13 mars 2026,…
https://cyberveille.ch/posts/2026-04-05-loldrivers-ajout-de-nouveaux-drivers-vulnerables-iobitunlocker-zemana-et-tfsysmon-utilises-en-byovd/ #BYOVD #Cyberveille
📝 ## 🔍 Contexte
Le 13 mars 2026,…
https://cyberveille.ch/posts/2026-04-05-loldrivers-ajout-de-nouveaux-drivers-vulnerables-iobitunlocker-zemana-et-tfsysmon-utilises-en-byovd/ #BYOVD #Cyberveille
Introduction: Living Off the Land (LOTL) attacks have become the cornerstone of modern adversarial tradecraft. By weaponizing legitimate, signed…
Introduction: Living Off the Land (LOTL) attacks have become the cornerstone of modern adversarial tradecraft. By weaponizing legitimate, signed…
Introduction: Endpoint Detection and Response (EDR) systems are the frontline defenders in modern cybersecurity, but attackers have shifted tactics—using legitimate administrative tools and…
Introduction: Endpoint Detection and Response (EDR) systems are the frontline defenders in modern cybersecurity, but attackers have shifted tactics—using legitimate administrative tools and…
Introduction: The Bring Your Own Vulnerable Driver (BYOVD) technique is a sophisticated post‑exploitation method where attackers load a legitimate but flawed kernel driver onto a system to gain…
Introduction: The Bring Your Own Vulnerable Driver (BYOVD) technique is a sophisticated post‑exploitation method where attackers load a legitimate but flawed kernel driver onto a system to gain…
Introduction: Living‑Off‑the‑Land Drivers (LOLDrivers) are signed, legitimate third‑party kernel drivers that attackers repurpose to bypass security controls, disable EDRs, and gain ring‑0…
Introduction: Living‑Off‑the‑Land Drivers (LOLDrivers) are signed, legitimate third‑party kernel drivers that attackers repurpose to bypass security controls, disable EDRs, and gain ring‑0…
Introduction: Bring Your Own Vulnerable Driver (BYOVD) attacks have become a preferred privilege escalation technique for ransomware gangs and advanced persistent threats (APTs).…
Introduction: Bring Your Own Vulnerable Driver (BYOVD) attacks have become a preferred privilege escalation technique for ransomware gangs and advanced persistent threats (APTs).…
Introduction: Bring Your Own Vulnerable Driver (BYOVD) attacks have become a preferred weapon for ransomware gangs like Qilin, allowing them to load malicious, signed-but-flawed…
Introduction: Bring Your Own Vulnerable Driver (BYOVD) attacks have become a preferred weapon for ransomware gangs like Qilin, allowing them to load malicious, signed-but-flawed…
Introduction: Microsoft’s cross-signed driver policy was designed to balance compatibility with security, but attackers have weaponized legacy trust relationships. Recent LOLDrivers data…
Introduction: Microsoft’s cross-signed driver policy was designed to balance compatibility with security, but attackers have weaponized legacy trust relationships. Recent LOLDrivers data…