#LOLDrivers
Its not on LOLDrivers.

Hmmm

:)

— from @_subTee (https://x.com/_subTee/status/2078087587173216322)
July 17, 2026 at 12:23 PM
One Person, 1,500 Endpoints, Two Hours a Week: How a Financial Services Firm Killed Its LOLBin & LOLDriver Exposure Without Adding a Single Agent + Video

Introduction: Living Off the Land (LOTL) attacks have become the cornerstone of modern adversarial tradecraft. By weaponizing legitimate, signed…
One Person, 1,500 Endpoints, Two Hours a Week: How a Financial Services Firm Killed Its LOLBin & LOLDriver Exposure Without Adding a Single Agent + Video
Introduction: Living Off the Land (LOTL) attacks have become the cornerstone of modern adversarial tradecraft. By weaponizing legitimate, signed binaries (LOLBins), vulnerable kernel drivers (LOLDrivers), and dual-use remote management tools (RMM), attackers can bypass traditional antivirus and EDR solutions entirely. For a U.S.-based financial services firm with 1,500 Windows endpoints and a mature security posture that already included AppLocker and WDAC, the gap wasn't a lack of tools—it was the operational burden of managing prevention at scale.
undercodetesting.com
June 28, 2026 at 3:15 PM
Automated BYOVD hunting pipeline - Scans Windows kernel drivers for dangerous imports, extracts IOCTL dispatch surfaces, cross-references against:
LOLDrivers
MS Blocklist
KDU
https://t.co/BVmUQG4JZL

— from @ipurple (https://x.com/ipurple/status/2071242151388749950)
GitHub - diabloidyobane/DriverScope: Automated BYOVD driver analysis: import scanning, IOCTL...
t.co
June 28, 2026 at 2:47 PM
Did people start vibe coding EDR killers by pointing the AI agent to LOLDrivers?

It certainly feels like it when I open LinkedIn in the morning.

— from @cyb3rops (https://x.com/cyb3rops/status/2070394339532898688)
June 26, 2026 at 6:56 AM
CISA, NSA, and FBI published joint guidance on Living Off the Land attacks. LOLDrivers and LOLRMM, built by our founders, are cited in it. MagicSword turns that intelligence into preventative controls…

🔁 RT @magicswordio | reposted by @_subTee
https://x.com/magicswordio/status/2067711666889130340
June 18, 2026 at 9:16 PM
DriverSentinel: an open-source Security Tool developed in Go that detects malicious and vulnerable Drivers on Windows systems by comparing them against the LOLDrivers\.io Database #Infosec #Vulnerability github.com/bI8d0/Driver...
GitHub - bI8d0/DriverSentinel: DriverSentinel is a security tool developed in Go that detects malicious and vulnerable drivers on Windows systems by comparing them against the LOLDrivers.io database.
DriverSentinel is a security tool developed in Go that detects malicious and vulnerable drivers on Windows systems by comparing them against the LOLDrivers.io database. - bI8d0/DriverSentinel
github.com
June 10, 2026 at 7:13 PM
How MagicSword Is Revolutionizing EDR Defense: Stopping EDR Killers Before They Run + Video

Introduction: Endpoint Detection and Response (EDR) systems are the frontline defenders in modern cybersecurity, but attackers have shifted tactics—using legitimate administrative tools and…
How MagicSword Is Revolutionizing EDR Defense: Stopping EDR Killers Before They Run + Video
Introduction: Endpoint Detection and Response (EDR) systems are the frontline defenders in modern cybersecurity, but attackers have shifted tactics—using legitimate administrative tools and living-off-the-land binaries (LOLBins) to disable or kill EDR agents without triggering traditional alarms. MagicSword’s approach focuses on defending the EDR itself, proactively stopping “EDR killers” that exploit trusted drivers (LOLDrivers) and remote management tools (LOLRMM) before they ever execute.
undercodetesting.com
June 9, 2026 at 10:22 PM
Someone in the community took the LOLDrivers API and built a full Windows app to detect vulnerable drivers.

Open source, clean implementation, did it the right way. This is exactly what the project w…

🔁 RT @magicswordio | reposted by @_subTee
https://x.com/magicswordio/status/2059697305662398525
GitHub - bI8d0/DriverSentinel: DriverSentinel is a security tool developed in Go that detects...
t.co
May 27, 2026 at 8:37 PM
BYOVD Attacks Exposed: The Vulnerable Lenovo Driver That Could Let Hackers Wreck Your Security + Video

Introduction: The Bring Your Own Vulnerable Driver (BYOVD) technique is a sophisticated post‑exploitation method where attackers load a legitimate but flawed kernel driver onto a system to gain…
BYOVD Attacks Exposed: The Vulnerable Lenovo Driver That Could Let Hackers Wreck Your Security + Video
Introduction: The Bring Your Own Vulnerable Driver (BYOVD) technique is a sophisticated post‑exploitation method where attackers load a legitimate but flawed kernel driver onto a system to gain Ring‑0 privileges, disable security software, and take full control. On May 8, 2026, security researcher Michael H. reported that a vulnerable Lenovo driver—CVE‑2025‑8061—had been added to the LOLDrivers database, reigniting concerns about how easily a signed driver can become an attacker’s weapon.
undercodetesting.com
May 20, 2026 at 4:59 PM
📢 LOLDrivers : ajout de nouveaux drivers vulnérables IoBitUnlocker, Zemana et TfSysMon utilisés en BYOVD
📝 ## 🔍 Contexte

Le 13 mars 2026,…
https://cyberveille.ch/posts/2026-04-05-loldrivers-ajout-de-nouveaux-drivers-vulnerables-iobitunlocker-zemana-et-tfsysmon-utilises-en-byovd/ #BYOVD #Cyberveille
May 7, 2026 at 1:30 AM
LOLDrivers dataset normalization update! We’ve standardized the naming across the dataset, moving from “vulnerable drivers” → “vulnerable driver” for consistency.

This builds on earlier work and hel…

🔁 RT @magicswordio | reposted by @HackingLZ
https://x.com/magicswordio/status/2050250259054387347
fix: normalize category from "vulnerable drivers" to "vulnerable driver" by adhikara13 · Pull...
t.co
May 1, 2026 at 4:41 PM
Hackers’ New Playbook: Exploiting IObitUnlocker, Zemana, and TfSysMon Drivers – Are You Protected? + Video

Introduction: Living‑Off‑the‑Land Drivers (LOLDrivers) are signed, legitimate third‑party kernel drivers that attackers repurpose to bypass security controls, disable EDRs, and gain ring‑0…
Hackers’ New Playbook: Exploiting IObitUnlocker, Zemana, and TfSysMon Drivers – Are You Protected? + Video
Introduction: Living‑Off‑the‑Land Drivers (LOLDrivers) are signed, legitimate third‑party kernel drivers that attackers repurpose to bypass security controls, disable EDRs, and gain ring‑0 persistence. The recent addition of real‑world vulnerable samples – IObitUnlocker, Zemana, and TfSysMon – to the MagicSword LOLDrivers project underscores an urgent reality: what defenders treat as benign utilities can become operational weaponry in a Bring Your Own Vulnerable Driver (BYOVD) attack.
undercodetesting.com
April 29, 2026 at 10:54 PM
LOLDrivers v20: 84 Signed Drivers Validated – How Attackers Weaponize Authenticode and You Can Stop BYOVD Now + Video

Introduction: Bring Your Own Vulnerable Driver (BYOVD) attacks have become a preferred privilege escalation technique for ransomware gangs and advanced persistent threats (APTs).…
LOLDrivers v20: 84 Signed Drivers Validated – How Attackers Weaponize Authenticode and You Can Stop BYOVD Now + Video
Introduction: Bring Your Own Vulnerable Driver (BYOVD) attacks have become a preferred privilege escalation technique for ransomware gangs and advanced persistent threats (APTs). Attackers load a legitimate but vulnerable signed driver to bypass kernel protections, then exploit it to disable endpoint detection or gain SYSTEM privileges. The LOLDrivers project recently validated 84 drivers with Authenticode signatures, fixing misclassified hashes that previously confused defenders.
undercodetesting.com
April 17, 2026 at 1:49 AM
Add vulnerable driver ASTRA64.sys (EnTech Taiwan / Sysinfo Lab) · Issue #294 · magicsword-io/LOLDrivers
Add vulnerable driver ASTRA64.sys (EnTech Taiwan / Sysinfo Lab) · Issue #294 · magicsword-io/LOLDrivers
github.com
April 9, 2026 at 11:54 PM
DetectRaptor publishes a VQL collection for Velociraptor with detections for Amcache, MFT, EVTX, YARA (Win/Linux/Mac), LolDrivers and bootloader indicators. #tool #velociraptor #vql https://bit.ly/3PSssXj
April 7, 2026 at 1:31 PM
Qilin’s EDR Killer Unleashed: How rwdrvsys and hlpdrvsys Bypass Your Defenses – And How LOLDrivers Fights Back + Video

Introduction: Bring Your Own Vulnerable Driver (BYOVD) attacks have become a preferred weapon for ransomware gangs like Qilin, allowing them to load malicious, signed-but-flawed…
Qilin’s EDR Killer Unleashed: How rwdrvsys and hlpdrvsys Bypass Your Defenses – And How LOLDrivers Fights Back + Video
Introduction: Bring Your Own Vulnerable Driver (BYOVD) attacks have become a preferred weapon for ransomware gangs like Qilin, allowing them to load malicious, signed-but-flawed kernel drivers to terminate endpoint detection and response (EDR) agents. The recent discovery of Qilin’s EDR killer leveraging `rwdrv.sys` and `hlpdrv.sys` highlights the urgent need for organizations to inventory and monitor drivers—a task that the open-source LOLDrivers project has already addressed for months.
undercodetesting.com
April 6, 2026 at 8:33 PM
LOLDrivers Exposed: How 1,620 Cross-Signed Drivers Bypass HVCI and Your Endpoint’s Last Line of Defense + Video

Introduction: Microsoft’s cross-signed driver policy was designed to balance compatibility with security, but attackers have weaponized legacy trust relationships. Recent LOLDrivers data…
LOLDrivers Exposed: How 1,620 Cross-Signed Drivers Bypass HVCI and Your Endpoint’s Last Line of Defense + Video
Introduction: Microsoft’s cross-signed driver policy was designed to balance compatibility with security, but attackers have weaponized legacy trust relationships. Recent LOLDrivers data reveals that nearly half of all malicious driver samples bypass Hypervisor-Protected Code Integrity (HVCI), and a single legacy driver stuck in evaluation mode can render all 1,620 known cross-signed samples loadable—meaning your “protected” endpoint is wide open. Learning Objectives:
undercodetesting.com
April 3, 2026 at 7:01 PM
CVE-2026-30769: New BYOVD Killer Enters the Arena—TVicPort64sys Weaponized for Kernel Takeover + Video

Introduction: The Bring Your Own Vulnerable Driver (BYOVD) attack technique continues to be a favored method for adversaries seeking to disable security controls and gain kernel-level privileges.…
CVE-2026-30769: New BYOVD Killer Enters the Arena—TVicPort64sys Weaponized for Kernel Takeover + Video
Introduction: The Bring Your Own Vulnerable Driver (BYOVD) attack technique continues to be a favored method for adversaries seeking to disable security controls and gain kernel-level privileges. By leveraging legitimate but vulnerable signed drivers, attackers can bypass user-mode protections and execute arbitrary code with SYSTEM privileges. The recent addition of TVicPort64.sys to the LOLDrivers project, assigned CVE-2026-30769, highlights a critical vulnerability in a driver signed as far back as 2006, enabling arbitrary physical memory mapping and local privilege escalation (LPE).
undercodetesting.com
March 24, 2026 at 12:29 AM
The Silent Invader: How LOLDrivers Are Exploiting Your Windows Systems and How to Stop Them + Video

Introduction: LOLDrivers, or "Living Off the Land Drivers," refer to legitimate but vulnerable Windows drivers that attackers exploit in Bring Your Own Vulnerable Driver (BYOVD) attacks to bypass…
The Silent Invader: How LOLDrivers Are Exploiting Your Windows Systems and How to Stop Them + Video
Introduction: LOLDrivers, or "Living Off the Land Drivers," refer to legitimate but vulnerable Windows drivers that attackers exploit in Bring Your Own Vulnerable Driver (BYOVD) attacks to bypass security controls like EDR and application whitelisting. With the recent update to the LOLDrivers project—adding newly-validated drivers, CVE alignments, and abuse patterns—the cybersecurity community must grapple with an expanding attack surface. This article breaks down the technical nuances of LOLDrivers and provides actionable steps for detection, mitigation, and hardening of Windows environments.
undercodetesting.com
January 14, 2026 at 11:49 PM
The Silent Infiltration: How Attackers Hijack Legitimate Drivers to Pwn the Kernel

Introduction: The cybersecurity landscape is witnessing a sophisticated shift in attacker tradecraft, moving beyond traditional malware to the weaponization of signed, legitimate software components. The recent…
The Silent Infiltration: How Attackers Hijack Legitimate Drivers to Pwn the Kernel
Introduction: The cybersecurity landscape is witnessing a sophisticated shift in attacker tradecraft, moving beyond traditional malware to the weaponization of signed, legitimate software components. The recent addition of `atillk64.sys` to the Living-Off-the-Land Drivers (LOLDrivers) repository underscores a critical threat: adversaries are exploiting trusted, signed drivers to gain unfettered kernel-level access, effectively dismantling security controls and compromising entire systems. Learning Objectives:
undercodetesting.com
November 22, 2025 at 4:33 PM
Unmasking LOLDrivers: How to Hunt Malicious Kernel-Level Threats

Introduction: The battle for control over operating systems has moved into the kernel, the most privileged part of the OS. LOLDrivers (Living-Off-the-Land Drivers) represent a critical threat, where attackers weaponize signed,…
Unmasking LOLDrivers: How to Hunt Malicious Kernel-Level Threats
Introduction: The battle for control over operating systems has moved into the kernel, the most privileged part of the OS. LOLDrivers (Living-Off-the-Land Drivers) represent a critical threat, where attackers weaponize signed, legitimate kernel drivers to bypass security controls. Understanding how to detect and hunt for these malicious drivers is paramount for modern defense. Learning Objectives: Understand the LOLDrivers project and how to leverage its database for threat intelligence.
undercodetesting.com
October 26, 2025 at 5:03 AM
📌 Silver Fox APT Exploits Signed Driver Vulnerability to Distribute ValleyRAT Malware https://www.cyberhub.blog/article/12728-silver-fox-apt-exploits-signed-driver-vulnerability-to-distribute-valleyrat-malware
Silver Fox APT Exploits Signed Driver Vulnerability to Distribute ValleyRAT Malware
Check Point has reported that the Silver Fox APT group is exploiting a vulnerability in a signed driver from WatchDog Antimalware to disable Windows security and distribute the ValleyRAT malware. This attack leverages a technique known as LOLDrivers, which involves using vulnerable, signed drivers to bypass security protections. The exploitation of this vulnerability allows Silver Fox to circumvent Windows defense mechanisms, facilitating the installation and execution of ValleyRAT. The technical implications of this attack are significant. Signed drivers are trusted components within an operating system. By exploiting vulnerabilities in these drivers, attackers can disable security features and gain unrestricted access to the system. This attack method highlights a critical vulnerability in the Windows security model, particularly in the handling of signed drivers. The impact on the cybersecurity landscape is substantial. This attack demonstrates how advanced threat actors can exploit trusted system components to carry out malicious activities. It underscores the need for robust patch management, continuous monitoring, and a defense-in-depth strategy to mitigate such threats. Cybersecurity professionals should be aware of this attack vector and ensure that all drivers and software are up-to-date with the latest security patches. Implementing advanced threat detection systems can help identify and respond to such sophisticated attacks. From an expert perspective, this attack reinforces the importance of threat intelligence and proactive defense measures. Organizations should regularly update their threat intelligence feeds to stay informed about emerging attack vectors and methods. Adopting a zero-trust approach, where no component is inherently trusted, can help mitigate the risk posed by such attacks.
www.cyberhub.blog
September 4, 2025 at 12:40 AM
The LOLDrivers MCP: Automating the Analysis of Malicious & Vulnerable Drivers

Introduction: The cybersecurity landscape is witnessing a paradigm shift in attacker techniques, with Living-Off-the-Land (LOL) binaries evolving to include kernel-level drivers. The LOLDrivers project, a vital community…
The LOLDrivers MCP: Automating the Analysis of Malicious & Vulnerable Drivers
Introduction: The cybersecurity landscape is witnessing a paradigm shift in attacker techniques, with Living-Off-the-Land (LOL) binaries evolving to include kernel-level drivers. The LOLDrivers project, a vital community resource for identifying these malicious and vulnerable drivers, has now integrated with the Model Context Protocol (MCP), enabling security researchers to automate and streamline their analysis workflows directly within their AI-assisted coding environments.
undercodetesting.com
August 28, 2025 at 6:01 PM
BYOVD Watchdog: A Game-Changer in Windows Kernel Security

Introduction: BYOVD (Bring Your Own Vulnerable Driver) attacks exploit unpatched or unsigned drivers to escalate privileges or bypass security mechanisms. Nikhil John Thomas’s BYOVD Watchdog tool addresses this by monitoring LOLDrivers…
BYOVD Watchdog: A Game-Changer in Windows Kernel Security
Introduction: BYOVD (Bring Your Own Vulnerable Driver) attacks exploit unpatched or unsigned drivers to escalate privileges or bypass security mechanisms. Nikhil John Thomas’s BYOVD Watchdog tool addresses this by monitoring LOLDrivers (Living-Off-the-Land Drivers) against Microsoft’s HVCI (Hypervisor-Protected Code Integrity) blocklist in real time, closing critical security gaps. Learning Objectives: Understand how BYOVD attacks exploit vulnerable drivers. Learn how BYOVD Watchdog enhances HVCI enforcement.
undercodetesting.com
July 27, 2025 at 3:54 AM