security-com · Crawled Jul 31, 2026

The BYOVD Epidemic: How Attackers Are Weaponizing Trusted Windows Drivers to Kill Security

1 IoCs 2 Malware
Read original article ↗

AI Summary

Attackers are increasingly leveraging the Bring Your Own Vulnerable Driver (BYOVD) technique to exploit legitimate, signed Windows kernel drivers and gain kernel-level privileges, enabling them to disable or bypass security software such as antivirus (AV) and endpoint detection and response (EDR) solutions. This method abuses flaws in trusted drivers like truesight.sys and those used by Microsoft Process Explorer, allowing attackers to terminate, suspend, or blind security processes. The technique has become widespread, with ready-made tools such as TrueSightKiller, GhostDriver, AuKill, and Poortry being integrated into ransomware-as-a-service (RaaS) offerings, making it a common component of modern ransomware attack chains.

AI-extracted · verify before operational use

Extracted Entities 2 found

Indicators of Compromise 1 extracted

Type Value Detail
Filename truesight.sys Details →

MITRE ATT&CK TTPs 5 techniques