Full Report
Discover how Bring Your Own Vulnerable Driver (BYOVD) tactics evolved from lone-operator tricks into a commercialized, tiered EDR-killer service economy.
Analysis Summary
# Tool/Technique: Bring Your Own Vulnerable Driver (BYOVD) / EDR-Killer Frameworks
## Overview
Bring Your Own Vulnerable Driver (BYOVD) is a technique where attackers with administrative privileges drop and load a legitimate, digitally signed, but vulnerable kernel-mode driver. Once loaded, the attacker exploits the driver's vulnerabilities to execute code in Ring 0 (kernel space), allowing them to disable, blind, or terminate Endpoint Detection and Response (EDR) agents and other security software that normally protect the system.
## Technical Details
- **Type:** Technique / Malware Family (EDR Killers)
- **Platform:** Windows (Kernel-mode)
- **Capabilities:** Kernel-level process termination, security product blinding, credential theft, and impersonation of legitimate services.
- **First Seen:** Early variants observed in 2023 (e.g., Terminator); significant commercialization and "framework" evolution noted in 2025–2026.
## MITRE ATT&CK Mapping
- **TA0005 - Defense Evasion**
- **T1068 - Exploitation for Privilege Escalation** (Abusing vulnerable drivers)
- **T1562.001 - Impair Defenses: Disable or Modify Tools** (Terminating EDR processes)
- **T1027 - Obfuscated Files or Information** (Impersonating legitimate security drivers)
- **TA0004 - Privilege Escalation**
- **T1068 - Exploitation for Privilege Escalation**
## Functionality
### Core Capabilities
- **Kernel-Level Termination:** Abuses `DeviceIoControl` calls to communicate with vulnerable drivers (e.g., Zemana, NSecsoft) to terminate protected security processes.
- **Broad Coverage:** Modern frameworks (like the one used by "hastalamuerte") target over 400 processes across 48 different security products.
- **Driver Abstraction:** Using "compatibility matrices" to load the most effective driver for the target environment.
### Advanced Features
- **Impersonation:** Each variant in the framework is designed to dress up as a legitimate security product to match the driver it is abusing, reducing the chance of detection by administrators.
- **Service Economy Integration:** Developed as a tiered software product with versions, support, and affiliate distribution models (RaaS).
- **Tool Bundling:** Often integrated with credential stealers (e.g., OxideHarvest) and automated ransomware deployment chains.
## Indicators of Compromise
- **File Names:** `HexKiller`, `ThrottleBlood`, `HavocKiller`, `AvNeutralizer`, `AuKill`, `Terminator`.
- **Drivers often abused:**
- `zemana.sys` / `zam64.sys` (Zemana)
- `gdrv.sys` (GIGABYTE)
- Drivers from NSecsoft, Qihoo 360, Safetica, TTD, and Process Explorer.
- **Behavioral Indicators:**
- Loading of known vulnerable drivers not associated with the system's intended hardware/software.
- Unexpected termination of `MsSense.exe`, `CyborgSoldier.exe`, or other EDR-related processes.
- Use of `sc.exe` or `LoadDriver` API calls to register unfamiliar kernel services.
## Associated Threat Actors
- **hastalamuerte** (RaaS operator)
- **FIN7** (Developers of AvNeutralizer/AuKill)
- **Black Basta, AvosLocker, MedusaLocker, BlackCat, LockBit** (Affiliates/Customers)
- **Qilin**
- **Spyboy** (Creator of Terminator)
- **RansomHub**
- **Reynolds Ransomware**
## Detection Methods
- **Signature-based detection:** Maintaining a blocklist of hashes for known vulnerable drivers (e.g., the LOLDrivers project).
- **Behavioral detection:** Monitoring for `DeviceIoControl` patterns that are typical of process termination from non-standard drivers.
- **YARA rules:** Targeting the specific headers and impersonation strings used in the EDR-killer frameworks.
- **Audit Logs:** Monitoring Event ID 7045 (Service Creation) for drivers not in a verified gold image.
## Mitigation Strategies
- **Microsoft Vulnerable Driver Blocklist:** Ensure Windows Defender / Microsoft Ecosystem blocklists are enabled and updated.
- **HVCI (Hypervisor-Protected Code Integrity):** Enable Memory Integrity to prevent unsigned or improperly signed code from executing in the kernel.
- **Principle of Least Privilege:** Restrict administrative rights, as BYOVD typically requires the ability to load a driver.
- **WDAC (Windows Defender Application Control):** Use strict policies to only allow known-good, authorized drivers.
## Related Tools/Techniques
- **LOLDrivers (Living Off the Land Drivers):** The repository of legitimate drivers used for malicious purposes.
- **OxideHarvest:** A credential stealer often bundled with EDR-killer suites.
- **Process Blinding:** Techniques used to hide malicious activity from security APIs without necessarily terminating the process.