#LOLDrivers
LOLDrivers are cool 😎
November 18, 2023 at 3:23 PM
#100DaysOfKQL

Day 24 - LOLDRIVERS Malicious Driver Observed or Loaded

Featuring the awesome LOLDrivers project from @magicswordio

Anything they release is amazing and worth integrating in your detection/threat hunting rules, check them out!

github.com/SecurityAura...
github.com
January 25, 2025 at 3:23 AM
LOLBins/Drivers Key resources:
→ LOLBAS: [lolbas-project.github.io](lolbas-project.github.io)
→ LOLDrivers: [loldrivers.io](www.loldrivers.io)
Detect abused tools & malicious drivers.
#LOLBins #LOLDrivers
LOLBAS
lolbas-project.github.io
January 26, 2025 at 2:24 AM
My summer associate Michael Lin wrote a powershell script to help you find out which vulnerable/malicious drivers from loldrivers.io will successfully load on your HVCI-enabled system: github.com/trailofbits/...
GitHub - trailofbits/HVCI-loldrivers-check
Contribute to trailofbits/HVCI-loldrivers-check development by creating an account on GitHub.
github.com
August 25, 2023 at 6:51 PM
LOLDrivers 1.0 has dropped: https://loldrivers.io
This list enumerates 593 unique SHA256 Authentihashes for vulnerable drivers.
Of this list, only 56 are on the Microsoft recommended driver block rules.🤔
May 9, 2023 at 1:30 AM
BYOVD is bad, but you can take proactive steps to prevent exploitation of known vulnerable drivers. A full list of all publicly known vulnerable drivers is available here:

https://github.com/magicsword-io/LOLDrivers

#cybersecurity

From: @screaminggoat […]
Original post on infosec.exchange
infosec.exchange
December 20, 2024 at 7:21 PM
Left: LOLDrivers SHA256 AuthentihashesRight: Microsoft driver block list SHA256 Authentihashes When I started looking last fall, MS driver blocking was simply broken in *multiple* ways. Perhaps it's now worth looking at what kind of a subset of known vulnerable drivers it is! 🤔
May 9, 2023 at 2:03 PM
The project is similar to other initiatives that track benign tools that can be abused for attacks on Windows (LOLBAS, LOLDrivers, and LOFLCAB), Linux (GTFOBins), macOS (LOOBins), CI/CD pipelines (LOTP), and ESXi VMs (LOLESXi).
October 31, 2024 at 3:03 PM
DriverSentinel: an open-source Security Tool developed in Go that detects malicious and vulnerable Drivers on Windows systems by comparing them against the LOLDrivers\.io Database #Infosec #Vulnerability github.com/bI8d0/Driver...
GitHub - bI8d0/DriverSentinel: DriverSentinel is a security tool developed in Go that detects malicious and vulnerable drivers on Windows systems by comparing them against the LOLDrivers.io database.
DriverSentinel is a security tool developed in Go that detects malicious and vulnerable drivers on Windows systems by comparing them against the LOLDrivers.io database. - bI8d0/DriverSentinel
github.com
June 10, 2026 at 7:13 PM
Its not on LOLDrivers.

Hmmm

:)

— from @_subTee (https://x.com/_subTee/status/2078087587173216322)
July 17, 2026 at 12:23 PM
DetectRaptor publishes a VQL collection for Velociraptor with detections for Amcache, MFT, EVTX, YARA (Win/Linux/Mac), LolDrivers and bootloader indicators. #tool #velociraptor #vql https://bit.ly/3PSssXj
April 7, 2026 at 1:31 PM
Add vulnerable driver ASTRA64.sys (EnTech Taiwan / Sysinfo Lab) · Issue #294 · magicsword-io/LOLDrivers
Add vulnerable driver ASTRA64.sys (EnTech Taiwan / Sysinfo Lab) · Issue #294 · magicsword-io/LOLDrivers
github.com
April 9, 2026 at 11:54 PM
Detecting Vulnerable Drivers (a.k.a. LOLDrivers) the Right Way
Detecting Vulnerable Drivers (a.k.a. LOLDrivers) the Right Way
academy.bluraven.io
June 2, 2025 at 10:24 AM
📢 LOLDrivers : ajout de nouveaux drivers vulnérables IoBitUnlocker, Zemana et TfSysMon utilisés en BYOVD
📝 ## 🔍 Contexte

Le 13 mars 2026,…
https://cyberveille.ch/posts/2026-04-05-loldrivers-ajout-de-nouveaux-drivers-vulnerables-iobitunlocker-zemana-et-tfsysmon-utilises-en-byovd/ #BYOVD #Cyberveille
May 7, 2026 at 1:30 AM
One Person, 1,500 Endpoints, Two Hours a Week: How a Financial Services Firm Killed Its LOLBin & LOLDriver Exposure Without Adding a Single Agent + Video

Introduction: Living Off the Land (LOTL) attacks have become the cornerstone of modern adversarial tradecraft. By weaponizing legitimate, signed…
One Person, 1,500 Endpoints, Two Hours a Week: How a Financial Services Firm Killed Its LOLBin & LOLDriver Exposure Without Adding a Single Agent + Video
Introduction: Living Off the Land (LOTL) attacks have become the cornerstone of modern adversarial tradecraft. By weaponizing legitimate, signed binaries (LOLBins), vulnerable kernel drivers (LOLDrivers), and dual-use remote management tools (RMM), attackers can bypass traditional antivirus and EDR solutions entirely. For a U.S.-based financial services firm with 1,500 Windows endpoints and a mature security posture that already included AppLocker and WDAC, the gap wasn't a lack of tools—it was the operational burden of managing prevention at scale.
undercodetesting.com
June 28, 2026 at 3:15 PM
How MagicSword Is Revolutionizing EDR Defense: Stopping EDR Killers Before They Run + Video

Introduction: Endpoint Detection and Response (EDR) systems are the frontline defenders in modern cybersecurity, but attackers have shifted tactics—using legitimate administrative tools and…
How MagicSword Is Revolutionizing EDR Defense: Stopping EDR Killers Before They Run + Video
Introduction: Endpoint Detection and Response (EDR) systems are the frontline defenders in modern cybersecurity, but attackers have shifted tactics—using legitimate administrative tools and living-off-the-land binaries (LOLBins) to disable or kill EDR agents without triggering traditional alarms. MagicSword’s approach focuses on defending the EDR itself, proactively stopping “EDR killers” that exploit trusted drivers (LOLDrivers) and remote management tools (LOLRMM) before they ever execute.
undercodetesting.com
June 9, 2026 at 10:22 PM
BYOVD Attacks Exposed: The Vulnerable Lenovo Driver That Could Let Hackers Wreck Your Security + Video

Introduction: The Bring Your Own Vulnerable Driver (BYOVD) technique is a sophisticated post‑exploitation method where attackers load a legitimate but flawed kernel driver onto a system to gain…
BYOVD Attacks Exposed: The Vulnerable Lenovo Driver That Could Let Hackers Wreck Your Security + Video
Introduction: The Bring Your Own Vulnerable Driver (BYOVD) technique is a sophisticated post‑exploitation method where attackers load a legitimate but flawed kernel driver onto a system to gain Ring‑0 privileges, disable security software, and take full control. On May 8, 2026, security researcher Michael H. reported that a vulnerable Lenovo driver—CVE‑2025‑8061—had been added to the LOLDrivers database, reigniting concerns about how easily a signed driver can become an attacker’s weapon.
undercodetesting.com
May 20, 2026 at 4:59 PM
Hackers’ New Playbook: Exploiting IObitUnlocker, Zemana, and TfSysMon Drivers – Are You Protected? + Video

Introduction: Living‑Off‑the‑Land Drivers (LOLDrivers) are signed, legitimate third‑party kernel drivers that attackers repurpose to bypass security controls, disable EDRs, and gain ring‑0…
Hackers’ New Playbook: Exploiting IObitUnlocker, Zemana, and TfSysMon Drivers – Are You Protected? + Video
Introduction: Living‑Off‑the‑Land Drivers (LOLDrivers) are signed, legitimate third‑party kernel drivers that attackers repurpose to bypass security controls, disable EDRs, and gain ring‑0 persistence. The recent addition of real‑world vulnerable samples – IObitUnlocker, Zemana, and TfSysMon – to the MagicSword LOLDrivers project underscores an urgent reality: what defenders treat as benign utilities can become operational weaponry in a Bring Your Own Vulnerable Driver (BYOVD) attack.
undercodetesting.com
April 29, 2026 at 10:54 PM
LOLDrivers v20: 84 Signed Drivers Validated – How Attackers Weaponize Authenticode and You Can Stop BYOVD Now + Video

Introduction: Bring Your Own Vulnerable Driver (BYOVD) attacks have become a preferred privilege escalation technique for ransomware gangs and advanced persistent threats (APTs).…
LOLDrivers v20: 84 Signed Drivers Validated – How Attackers Weaponize Authenticode and You Can Stop BYOVD Now + Video
Introduction: Bring Your Own Vulnerable Driver (BYOVD) attacks have become a preferred privilege escalation technique for ransomware gangs and advanced persistent threats (APTs). Attackers load a legitimate but vulnerable signed driver to bypass kernel protections, then exploit it to disable endpoint detection or gain SYSTEM privileges. The LOLDrivers project recently validated 84 drivers with Authenticode signatures, fixing misclassified hashes that previously confused defenders.
undercodetesting.com
April 17, 2026 at 1:49 AM
Qilin’s EDR Killer Unleashed: How rwdrvsys and hlpdrvsys Bypass Your Defenses – And How LOLDrivers Fights Back + Video

Introduction: Bring Your Own Vulnerable Driver (BYOVD) attacks have become a preferred weapon for ransomware gangs like Qilin, allowing them to load malicious, signed-but-flawed…
Qilin’s EDR Killer Unleashed: How rwdrvsys and hlpdrvsys Bypass Your Defenses – And How LOLDrivers Fights Back + Video
Introduction: Bring Your Own Vulnerable Driver (BYOVD) attacks have become a preferred weapon for ransomware gangs like Qilin, allowing them to load malicious, signed-but-flawed kernel drivers to terminate endpoint detection and response (EDR) agents. The recent discovery of Qilin’s EDR killer leveraging `rwdrv.sys` and `hlpdrv.sys` highlights the urgent need for organizations to inventory and monitor drivers—a task that the open-source LOLDrivers project has already addressed for months.
undercodetesting.com
April 6, 2026 at 8:33 PM
LOLDrivers Exposed: How 1,620 Cross-Signed Drivers Bypass HVCI and Your Endpoint’s Last Line of Defense + Video

Introduction: Microsoft’s cross-signed driver policy was designed to balance compatibility with security, but attackers have weaponized legacy trust relationships. Recent LOLDrivers data…
LOLDrivers Exposed: How 1,620 Cross-Signed Drivers Bypass HVCI and Your Endpoint’s Last Line of Defense + Video
Introduction: Microsoft’s cross-signed driver policy was designed to balance compatibility with security, but attackers have weaponized legacy trust relationships. Recent LOLDrivers data reveals that nearly half of all malicious driver samples bypass Hypervisor-Protected Code Integrity (HVCI), and a single legacy driver stuck in evaluation mode can render all 1,620 known cross-signed samples loadable—meaning your “protected” endpoint is wide open. Learning Objectives:
undercodetesting.com
April 3, 2026 at 7:01 PM