avalueio.sys
The Carbon Black Threat Analysis Unit (TAU) discovered 34 unique vulnerable drivers (237 file hashes) accepting firmware access. Six allow kernel memory access. All give full control of the devices to non-admin users. By exploiting the vulnerable drivers, an attacker without the system privilege may erase/alter firmware, and/or elevate privileges. As of the time of writing in October 2023, the filenames of the vulnerable drivers have not been made public until now.
Categories: vulnerable driver, verified
View authoritative reference β
a9df5964635ef8bd567ae487c3d214c4.sys
Cisco Talos has identified multiple versions of an undocumented malicious driver named βRedDriver,β a driver-based browser hijacker that uses the Windows Filtering Platform (WFP) to intercept browser traffic. RedDriver has been active since at least 2021. RedDriver utilizes HookSignTool to forge its signature timestamp to bypass Windows driver-signing policies. Code from multiple open-source tools has been used in the development of RedDriver's infection chain, including HP-Socket and a custom implementation of ReflectiveLoader. The authors of RedDriver appear to be skilled in driver development and have deep knowledge of the Windows operating system. This threat appears to target native Chinese speakers, as it searches for Chinese language browsers to hijack. Additionally, the authors are likely Chinese speakers themselves.
Categories: malicious, verified
View authoritative reference β
e29f6311ae87542b3d693c1f38e4e3ad.sys
Cisco Talos has identified multiple versions of an undocumented malicious driver named βRedDriver,β a driver-based browser hijacker that uses the Windows Filtering Platform (WFP) to intercept browser traffic. RedDriver has been active since at least 2021. RedDriver utilizes HookSignTool to forge its signature timestamp to bypass Windows driver-signing policies. Code from multiple open-source tools has been used in the development of RedDriver's infection chain, including HP-Socket and a custom implementation of ReflectiveLoader. The authors of RedDriver appear to be skilled in driver development and have deep knowledge of the Windows operating system. This threat appears to target native Chinese speakers, as it searches for Chinese language browsers to hijack. Additionally, the authors are likely Chinese speakers themselves.
Categories: malicious, verified
View authoritative reference β
DBUtilDrv2.sys
Dell DBUtilDrv2.sys versions 2.5, 2.6, and 2.7 all contain a write-what-where condition allowing kernel memory read/write. Dell released v2.7 as a remediation for CVE-2021-36276 but the fix was incomplete. Rapid7 confirmed v2.7 retains the kernel memory primitive and published the dellicious PoC and a Metasploit module (post/windows/manage/dell_memory_protect) that works against both v2.5 and v2.7. Dell categorized the v2.7 issue as a weakness rather than a vulnerability, stating it requires admin privileges.
Categories: vulnerable driver, verified
View authoritative reference β
GLCKIO2.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, verified
View authoritative reference β
sfdrvx64.sys
Confirmed vulnerable driver from Microsoft Block List
Categories: vulnerable driver, verified
View authoritative reference β
xhunter2.sys
Wellbia xhunter2.sys version 2026.6.1.192 is an XIGNCODE3 anti-cheat kernel component affected by CVE-2026-15430. Public research demonstrates bypasses for its module, caller, and request authentication layers, exposing privileged command paths for cross-process memory access, protected-process handle creation, process termination, local privilege escalation, and kernel-assisted code injection.
Categories: vulnerable driver, verified
View authoritative reference β
SmSerl64.sys
A vulnerability exits in driver SmSerl64.sys in Motorola SM56 Modem WDM Driver v6.12.23.0, which allows low-privileged users to mapping physical memory via specially crafted IOCTL requests . This can be exploited for privilege escalation, code execution under high privileges, and information disclosure. These signed drivers can also be used to bypass the Microsoft driver-signing policy to deploy malicious code.
Categories: vulnerable driver, verified
View authoritative reference β
daxin_blank4.sys
Driver used in the Daxin malware campaign.
Categories: malicious, verified
View authoritative reference β
wantd_6.sys
Driver used in the Daxin malware campaign.
Categories: malicious, verified
View authoritative reference β
LMIinfo.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, verified
View authoritative reference β
rspot.sys
Rising Antivirus rspot.sys driver with kernel-level process termination capabilities. Identified in ESET EDR killers research (March 2026) as actively abused by threat actors to disable EDR products.
Categories: vulnerable driver, verified
View authoritative reference β
nxeng.sys
nxeng.sys is a vulnerable kernel driver from the KeServiceDescriptorTable/vulnerable-drivers repository. The driver exposes dangerous kernel primitives to usermode.
Categories: vulnerable driver, verified
View authoritative reference β
etdsupp.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, verified
View authoritative reference β
vsdatant.sys
Check Point ZoneAlarm driver (vsdatant.sys) abused in BYOVD attacks to gain kernel privileges and bypass protections such as Memory Integrity.
Categories: vulnerable driver, verified
View authoritative reference β
dellinstrumentation.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, verified
View authoritative reference β
wantd_3.sys
Driver used in the Daxin malware campaign.
Categories: malicious, verified
View authoritative reference β
semav6msr.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, verified
View authoritative reference β
DirectIo32.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, verified
View authoritative reference β
TmComm.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, verified
View authoritative reference β
inetcache.sys
inetcache.sys is a vulnerable kernel driver from the KeServiceDescriptorTable/vulnerable-drivers repository. The driver exposes dangerous kernel primitives to usermode.
Categories: vulnerable driver, verified
View authoritative reference β
WinIO32A.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, unverified
View authoritative reference β
tdeio64.sys
The Carbon Black Threat Analysis Unit (TAU) discovered 34 unique vulnerable drivers (237 file hashes) accepting firmware access. Six allow kernel memory access. All give full control of the devices to non-admin users. By exploiting the vulnerable drivers, an attacker without the system privilege may erase/alter firmware, and/or elevate privileges. As of the time of writing in October 2023, the filenames of the vulnerable drivers have not been made public until now.
Categories: vulnerable driver, verified
View authoritative reference β
ImmunetUtilDriver.sys
ImmunetUtilDriver.sys is a vulnerable kernel driver from the KeServiceDescriptorTable/vulnerable-drivers repository. The driver exposes dangerous kernel primitives to usermode.
Categories: vulnerable driver, verified
View authoritative reference β
kdriver.sys
Confirmed vulnerable driver from Microsoft Block List
Categories: vulnerable driver, verified
View authoritative reference β
WinFlash64.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, verified
View authoritative reference β
SysFile_X64.sys
SysFile_X64.sys is a vulnerable kernel driver from the KeServiceDescriptorTable/vulnerable-drivers repository. The driver exposes dangerous kernel primitives to usermode.
Categories: vulnerable driver, verified
View authoritative reference β
IOMap64.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, verified
View authoritative reference β
DDDriver.sys
DDDriver.sys is a vulnerable kernel driver from the KeServiceDescriptorTable/vulnerable-drivers repository. The driver exposes dangerous kernel primitives to usermode.
Categories: vulnerable driver, verified
View authoritative reference β
signeddrv.sys
signeddrv.sys is a Microsoft-signed vulnerable kernel driver that exposes an unrestricted \\.\WinNotify device. Public research documents IOCTL 0x22200C for kernel base disclosure, IOCTL 0x222040 for arbitrary kernel read, and IOCTL 0x222044 for arbitrary kernel write, enabling local privilege escalation.
Categories: vulnerable driver, verified
View authoritative reference β
CITMDRV_IA64.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, verified
View authoritative reference β
PanIO.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, unverified
View authoritative reference β
TmComm.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, verified
View authoritative reference β
cpuz141.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, verified
View authoritative reference β
xjokercontroller.sys
Confirmed vulnerable driver from Microsoft Block List
Categories: vulnerable driver, verified
View authoritative reference β
Air_SYSTEM10.sys
Driver categorized as POORTRY by Mandiant.
Categories: malicious, verified
View authoritative reference β
f.sys
Sophos, from time to time, has observed a threat actor deploy variants
of Poortry on different machines within a single estate during an attack. These
variants contain the same payload, but signed with a different certificate than
the driver first seen used during the attack.
Categories: malicious, verified
View authoritative reference β
BS_HWMIO64_W10.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, verified
View authoritative reference β
mtcBSv64.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, verified
View authoritative reference β
driver_d9f15d91.sys
Sophos, from time to time, has observed a threat actor deploy variants of Poortry on different machines within a single estate during an attack. These variants contain the same payload, but signed with a different certificate than the driver first seen used during the attack.
Categories: malicious, verified
View authoritative reference β
BS_Flash64.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, verified
View authoritative reference β
Mnemosyne.sys
Mnemosyne.sys is a vulnerable kernel driver from the KeServiceDescriptorTable/vulnerable-drivers repository. The driver exposes dangerous kernel primitives to usermode.
Categories: vulnerable driver, verified
View authoritative reference β
VBoxTAP.sys
Confirmed vulnerable driver from Microsoft Block List
Categories: vulnerable driver, verified
View authoritative reference β
DirectIo.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, verified
View authoritative reference β
HWiNFO32.SYS
Confirmed vulnerable driver from Microsoft Block List
Categories: vulnerable driver, verified
View authoritative reference β
CITMDRV_AMD64.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, verified
View authoritative reference β
kerneld.amd64
The Carbon Black Threat Analysis Unit (TAU) discovered 34 unique vulnerable drivers (237 file hashes) accepting firmware access. Six allow kernel memory access. All give full control of the devices to non-admin users. By exploiting the vulnerable drivers, an attacker without the system privilege may erase/alter firmware, and/or elevate privileges. As of the time of writing in October 2023, the filenames of the vulnerable drivers have not been made public until now.
Categories: vulnerable driver, verified
View authoritative reference β
AsUpIO.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, verified
View authoritative reference β
evga_kernel_driver-x64.sys
evga_kernel_driver-x64.sys is a vulnerable kernel driver from the KeServiceDescriptorTable/vulnerable-drivers repository. The driver exposes dangerous kernel primitives to usermode.
Categories: vulnerable driver, verified
View authoritative reference β
UCOREW64.SYS
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, verified
View authoritative reference β
Proxy64.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, unverified
View authoritative reference β
reddriver.sys
Cisco Talos has identified multiple versions of an undocumented malicious driver named βRedDriver,β a driver-based browser hijacker that uses the Windows Filtering Platform (WFP) to intercept browser traffic. RedDriver has been active since at least 2021.
RedDriver utilizes HookSignTool to forge its signature timestamp to bypass Windows driver-signing policies.
Code from multiple open-source tools has been used in the development of RedDriver's infection chain, including HP-Socket and a custom implementation of ReflectiveLoader.
The authors of RedDriver appear to be skilled in driver development and have deep knowledge of the Windows operating system.
This threat appears to target native Chinese speakers, as it searches for Chinese language browsers to hijack. Additionally, the authors are likely Chinese speakers themselves.
Categories: malicious, verified
View authoritative reference β
MsIo64.sys
The MSI AmbientLink MsIo64 driver 1.0.0.8 has a Buffer Overflow (0x80102040, 0x80102044, 0x80102050,and 0x80102054)
Categories: vulnerable driver, verified
View authoritative reference β
phymem_ext64.sys
The Carbon Black Threat Analysis Unit (TAU) discovered 34 unique vulnerable drivers (237 file hashes) accepting firmware access. Six allow kernel memory access. All give full control of the devices to non-admin users. By exploiting the vulnerable drivers, an attacker without the system privilege may erase/alter firmware, and/or elevate privileges. As of the time of writing in October 2023, the filenames of the vulnerable drivers have not been made public until now.
Categories: vulnerable driver, verified
View authoritative reference β
PcieCubed.sys
Driver categorized as POORTRY by Mandiant.
Categories: malicious, verified
View authoritative reference β
daxin_blank3.sys
Driver used in the Daxin malware campaign.
Categories: malicious, verified
View authoritative reference β
kEvP64.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, verified
View authoritative reference β
8492937_2_Driver.sys
ABYSSWORKER is a malicious driver used in MEDUSA ransomware attacks to disable EDR systems. The driver masquerades as a legitimate CrowdStrike Falcon driver and provides extensive capabilities to terminate processes, remove security callbacks, manipulate files, and disable security tools. It uses stolen certificates from Chinese companies and requires a specific password for activation. The driver was observed being deployed alongside HEARTCRYPT-packed loaders and provides attackers with kernel-level capabilities to blind EDR products by removing notification callbacks, detaching mini-filter devices, and replacing driver major functions.
Categories: vulnerable driver, verified
View authoritative reference β
inpout32.sys
Confirmed vulnerable driver from Microsoft Block List
Categories: vulnerable driver, verified
View authoritative reference β
SysInfo.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, verified
View authoritative reference β
POORTRY1.sys
Driver categorized as POORTRY by Mandiant.
Categories: malicious, verified
View authoritative reference β
fekern.sys
Trellix HX Agent fekern.sys 34.x is affected by CVE-2025-14963. The signed FireEye 34.5.0 and 34.8.0 builds tracked here expose the \\Device\\fekern_00 interface. Used as a standalone BYOVD, the vulnerable driver can provide access to LSASS memory and enable local privilege escalation. A fully functioning HX Agent restricts access through tamper protection.
Categories: vulnerable driver, verified
View authoritative reference β
segwindrvx64.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, verified
View authoritative reference β
BS_RCIOW1064.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, verified
View authoritative reference β
fbiosdrv.sys
Fujitsu BIOS Driver versions before 2.5.0.0 are affected by CVE-2025-65001. The tracked 1.2.1.0 through 2.4.0.0 fBiosDrv.sys builds all precede the fixed release. A crafted request from a local authenticated administrator can trigger an out-of-bounds write, potentially causing arbitrary kernel code execution or denial of service.
Categories: vulnerable driver, verified
View authoritative reference β
lsigetwin_SliffDriver.sys
lsigetwin_SliffDriver.sys is a Microsoft-signed vulnerable kernel driver that exposes a \\.\SliffDriver device. Public research documents IOCTL 0x80002004 for mapping caller-supplied physical memory into user mode, enabling local privilege escalation when chained with kernel address discovery and virtual-to-physical translation primitives.
Categories: vulnerable driver, verified
View authoritative reference β
bs_hwmio64.sys
Confirmed vulnerable driver from Microsoft Block List
Categories: vulnerable driver, verified
View authoritative reference β
BS_I2c64.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, verified
View authoritative reference β
TVicPort64.sys
Load TVicPort64.sys kernel driver. Once loaded, device \\.\TVicPortDevice0 is accessible from any integrity level (no DACL). Send IOCTL 0x80002008 to map arbitrary physical memory into user-mode VA space via ZwMapViewOfSection and perform token stealing for LPE to SYSTEM.
Categories: vulnerable driver, verified
View authoritative reference β
aswVmm.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, verified
View authoritative reference β
ControlCenter.sys
ControlCenter.sys is a vulnerable kernel driver from the KeServiceDescriptorTable/vulnerable-drivers repository. The driver exposes dangerous kernel primitives to usermode.
Categories: vulnerable driver, verified
View authoritative reference β
FairplayKD.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, unverified
View authoritative reference β
BSMI.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, verified
View authoritative reference β
vmdrv.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, verified
View authoritative reference β
d39DuiY9sxtDSiu4LSvS.sys
This purpose-built kernel loader creates the \\.\wifis device and accepts encrypted PE images through IOCTL 0x222000. Its worker thread decrypts input with an RC4-like routine using the embedded key dsmjklsafbv, manually maps the supplied PE image, resolves imports and relocations, and transfers execution to the unsigned payload in kernel memory.
Categories: malicious, verified
View authoritative reference β
asrdrv104.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, unverified
View authoritative reference β
cpuz.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, verified
View authoritative reference β
driver_82d928c5.sys
Sophos, from time to time, has observed a threat actor deploy variants of Poortry on different machines within a single estate during an attack. These variants contain the same payload, but signed with a different certificate than the driver first seen used during the attack.
Categories: malicious, verified
View authoritative reference β
BdApiUtil64.sys
Driver can be used to load unsigned drivers
Categories: vulnerable driver, verified
View authoritative reference β
avkiller.sys
Sophos, from time to time, has observed a threat actor deploy variants
of Poortry on different machines within a single estate during an attack. These
variants contain the same payload, but signed with a different certificate than
the driver first seen used during the attack.
Categories: malicious, verified
View authoritative reference β
fjfwupgd.sys
fjfwupgd.sys is a vulnerable kernel driver from the KeServiceDescriptorTable/vulnerable-drivers repository. The driver exposes dangerous kernel primitives to usermode.
Categories: vulnerable driver, verified
View authoritative reference β
CorsairLLAccess64.sys
Corsair LL Access 1.0.22.0 maps caller-selected physical addresses with MmMapIoSpace and can expose the mapped pages to user mode through MmMapLockedPagesSpecifyCache. These physical-memory access primitives can be abused for kernel tampering by an attacker able to load and open the driver.
Categories: vulnerable driver, verified
View authoritative reference β
CorsairLLAccess64.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, verified
View authoritative reference β
windbg.sys
These samples are related to CopperStealth campaign found by TrendMicro. CopperStealthβs infection chain involves dropping and loading a rootkit, which later injects its payload into explorer.exe and another system process. These payloads are responsible for downloading and running additional tasks. The rootkit also blocks access to blocklisted registry keys and prevents certain executables and drivers from running.
Categories: malicious, verified
View authoritative reference β
AODDriver.sys
The Carbon Black Threat Analysis Unit (TAU) discovered 34 unique vulnerable drivers (237 file hashes) accepting firmware access. Six allow kernel memory access. All give full control of the devices to non-admin users. By exploiting the vulnerable drivers, an attacker without the system privilege may erase/alter firmware, and/or elevate privileges. As of the time of writing in October 2023, the filenames of the vulnerable drivers have not been made public until now.
Categories: vulnerable driver, verified
View authoritative reference β
daxin_blank2.sys
Driver used in the Daxin malware campaign.
Categories: malicious, verified
View authoritative reference β
aswArPot.sys
Avast and AVG Anti Rootkit driver aswArPot.sys versions before 22.1 are affected by CVE-2022-26522 and CVE-2022-26523. Double-fetch races in kernel handlers allow a non-administrator user to corrupt kernel memory and execute code in kernel context, enabling local privilege escalation and security-product bypass.
Categories: vulnerable driver, verified
View authoritative reference β
d591004.sys
d591004.sys is a vulnerable kernel driver from the KeServiceDescriptorTable/vulnerable-drivers repository. The driver exposes dangerous kernel primitives to usermode.
Categories: vulnerable driver, verified
View authoritative reference β
isodrivep64.sys
ABYSSWORKER is a malicious driver used in MEDUSA ransomware attacks to disable EDR systems. The driver masquerades as a legitimate CrowdStrike Falcon driver and provides extensive capabilities to terminate processes, remove security callbacks, manipulate files, and disable security tools. It uses stolen certificates from Chinese companies and requires a specific password for activation. The driver was observed being deployed alongside HEARTCRYPT-packed loaders and provides attackers with kernel-level capabilities to blind EDR products by removing notification callbacks, detaching mini-filter devices, and replacing driver major functions.
Categories: vulnerable driver, verified
View authoritative reference β
AsrDrv101.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, verified
View authoritative reference β
SysInfoDetectorX64.sys
The Carbon Black Threat Analysis Unit (TAU) discovered 34 unique vulnerable drivers (237 file hashes) accepting firmware access. Six allow kernel memory access. All give full control of the devices to non-admin users. By exploiting the vulnerable drivers, an attacker without the system privilege may erase/alter firmware, and/or elevate privileges. As of the time of writing in October 2023, the filenames of the vulnerable drivers have not been made public until now.
Categories: vulnerable driver, verified
View authoritative reference β
driver_4f9b5a2f.sys
Sophos, from time to time, has observed a threat actor deploy variants of Poortry on different machines within a single estate during an attack. These variants contain the same payload, but signed with a different certificate than the driver first seen used during the attack.
Categories: malicious, verified
View authoritative reference β
CSAgent.sys
AbyssWorker rootkit masquerading as a CrowdStrike Falcon sensor driver (CSAgent.sys). Signed with a revoked certificate from Shenzhen yundian Technology Co., Ltd. This is a fully malicious driver that blinds security products by stripping handles, terminating processes, and removing notification callbacks. Identified in ESET EDR killers research (March 2026) deployed alongside Medusa ransomware via the HEARTCRYPT packer.
Categories: malicious, verified
View authoritative reference β
MonProcessEX.sys
MonProcessEX.sys is a HONOR MagicAnimation and HONOR PCManager kernel driver that exposes IOCTL 0x22400C to reach ZwTerminateProcess. The device is accessible to LocalSystem and local administrators, and the process-termination path does not verify the caller, allowing an administrator-accessible client to terminate arbitrary user-mode processes except PID 0 and PID 4 from kernel mode.
Categories: vulnerable driver, verified
View authoritative reference β
giveio.sys
The 32-bit giveio driver bundled with SpeedFan creates the \\.\giveio device and handles IRP_MJ_CREATE by applying a zeroed 8 KiB I/O permission map to the opening process through Ke386IoSetAccessProcess and Ke386SetIoAccessMap. This grants unrestricted direct access to all x86 I/O ports without validating the caller.
Categories: vulnerable driver, verified
View authoritative reference β
nvflash.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, verified
View authoritative reference β
fur.sys
SophosLabs has discovered that threat actors are using a new driver loader called BURNTCIGAR to install a malicious driver signed with Microsoft.
Categories: malicious, verified
View authoritative reference β
driver_5d61e4ea.sys
Sophos, from time to time, has observed a threat actor deploy variants of Poortry on different machines within a single estate during an attack. These variants contain the same payload, but signed with a different certificate than the driver first seen used during the attack.
Categories: malicious, verified
View authoritative reference β
ComputerZ.Sys
The Carbon Black Threat Analysis Unit (TAU) discovered 34 unique vulnerable drivers (237 file hashes) accepting firmware access. Six allow kernel memory access. All give full control of the devices to non-admin users. By exploiting the vulnerable drivers, an attacker without the system privilege may erase/alter firmware, and/or elevate privileges. As of the time of writing in October 2023, the filenames of the vulnerable drivers have not been made public until now.
Categories: vulnerable driver, verified
View authoritative reference β
NlsLexicons0024UvN.sys
Cisco Talos has identified multiple versions of an undocumented malicious driver named βRedDriver,β a driver-based browser hijacker that uses the Windows Filtering Platform (WFP) to intercept browser traffic. RedDriver has been active since at least 2021.
RedDriver utilizes HookSignTool to forge its signature timestamp to bypass Windows driver-signing policies.
Code from multiple open-source tools has been used in the development of RedDriver's infection chain, including HP-Socket and a custom implementation of ReflectiveLoader.
The authors of RedDriver appear to be skilled in driver development and have deep knowledge of the Windows operating system.
This threat appears to target native Chinese speakers, as it searches for Chinese language browsers to hijack. Additionally, the authors are likely Chinese speakers themselves.
Categories: malicious, verified
View authoritative reference β
WinRing0.sys
OpenLibSys WinRing0 hardware-access drivers expose MSR, I/O-port, and physical-memory operations to user mode. Attackers can abuse these primitives for kernel-memory access and security-control tampering.
Categories: vulnerable driver, verified
View authoritative reference β
vmdrv.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, verified
View authoritative reference β
driver_b4f33ffe.sys
Sophos, from time to time, has observed a threat actor deploy variants of Poortry on different machines within a single estate during an attack. These variants contain the same payload, but signed with a different certificate than the driver first seen used during the attack.
Categories: malicious, verified
View authoritative reference β
ppa_x64.sys
ppa_x64.sys is a kernel driver by Remko Weijnen that provides physical memory access via the PhysicalMemory section object. The device name PhyMem indicates this is part of the PhyMem driver family, of which several variants are already tracked in LOLDrivers (phymem64.sys, Phymemx64.sys, phymem_ext64.sys). The driver is available in the KeServiceDescriptorTable/vulnerable-drivers repository.
Categories: vulnerable driver, verified
View authoritative reference β
KKYUM.sys
The driver creates a device object named "\\.\KKYUM" without strict access controls, allowing low-privileged users to interact with it. It exposes unauthenticated IOCTL control codes "0x22265C" (Read) and "0x222658" (Write) that encapsulate the MmCopyVirtualMemory kernel API. The handler accepts a target Process ID (PID) and a structured array of source/destination virtual addresses directly from user space without checking execution privileges, enabling local attackers to perform unauthorized arbitrary process memory reads and writes against any active process.
Categories: vulnerable driver, verified
View authoritative reference β
nstr.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, unverified
View authoritative reference β
LnvMSRIO.sys
LnvMSRIO.sys is a Lenovo Dispatcher driver affected by CVE-2025-8061. The tracked 3.0.2.28 through 3.1.0.36 builds predate Lenovo's fixed 3.1.0.41 driver. The WinMsrDev interface exposes physical-memory read and write through IOCTLs 0x9C406104 and 0x9C40A108 and MSR read and write through 0x9C402084 and 0x9C402088, allowing an authenticated local user to execute code with elevated privileges when Memory Integrity is not enabled.
Categories: vulnerable driver, verified
View authoritative reference β
e939448b28a4edc81f1f974cebf6e7d2.sys
Cisco Talos has identified multiple versions of an undocumented malicious driver named βRedDriver,β a driver-based browser hijacker that uses the Windows Filtering Platform (WFP) to intercept browser traffic. RedDriver has been active since at least 2021. RedDriver utilizes HookSignTool to forge its signature timestamp to bypass Windows driver-signing policies. Code from multiple open-source tools has been used in the development of RedDriver's infection chain, including HP-Socket and a custom implementation of ReflectiveLoader. The authors of RedDriver appear to be skilled in driver development and have deep knowledge of the Windows operating system. This threat appears to target native Chinese speakers, as it searches for Chinese language browsers to hijack. Additionally, the authors are likely Chinese speakers themselves.
Categories: malicious, verified
View authoritative reference β
daxin_blank5.sys
Driver used in the Daxin malware campaign.
Categories: malicious, verified
View authoritative reference β
LgDCatcher.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, verified
View authoritative reference β
IoManager.sys
IoManager.sys is a vulnerable kernel driver from the KeServiceDescriptorTable/vulnerable-drivers repository. The driver exposes dangerous kernel primitives to usermode.
Categories: vulnerable driver, verified
View authoritative reference β
AMDRyzenMasterDriver.sys
AMD Ryzen Master drivers affected by CVE-2023-20564 insufficiently validate IOCTL input buffers. A privileged caller can read or write memory through the exposed interface, potentially enabling arbitrary kernel execution.
Categories: vulnerable driver, verified
View authoritative reference β
hwdetectng.sys
The Carbon Black Threat Analysis Unit (TAU) discovered 34 unique vulnerable drivers (237 file hashes) accepting firmware access. Six allow kernel memory access. All give full control of the devices to non-admin users. By exploiting the vulnerable drivers, an attacker without the system privilege may erase/alter firmware, and/or elevate privileges. As of the time of writing in October 2023, the filenames of the vulnerable drivers have not been made public until now.
Categories: vulnerable driver, verified
View authoritative reference β
ardrv.sys
OPSWAT AppRemover ardrv.sys version 2017.10.02.1551 and earlier exposes a user-accessible \\.\ardrv device. Public research documents IOCTL 0x2420031 reaching process-termination paths, including ZwTerminateProcess, without sufficient caller or target validation. This allows local users to terminate arbitrary processes, including security tooling, and makes the driver useful in BYOVD-style defense impairment after it is loaded. Acronis observed the tracked ardrv.sys variant in an August 2026 campaign where it was used to terminate Microsoft Defender, Huorong, and Tencent security processes before SparkRAT deployment.
Categories: vulnerable driver, verified
View authoritative reference β
VBoxDrv.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, verified
View authoritative reference β
NBIOLib_X64.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, verified
View authoritative reference β
PMAD.sys
PMAD.sys is a vulnerable kernel driver from the KeServiceDescriptorTable/vulnerable-drivers repository. The driver exposes dangerous kernel primitives to usermode.
Categories: vulnerable driver, verified
View authoritative reference β
atillk64.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, verified
View authoritative reference β
nt2.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, unverified
View authoritative reference β
CSAgent.sys
ABYSSWORKER is a malicious driver used in MEDUSA ransomware attacks to disable EDR systems. The driver masquerades as a legitimate CrowdStrike Falcon driver and provides extensive capabilities to terminate processes, remove security callbacks, manipulate files, and disable security tools. It uses stolen certificates from Chinese companies and requires a specific password for activation. The driver was observed being deployed alongside HEARTCRYPT-packed loaders and provides attackers with kernel-level capabilities to blind EDR products by removing notification callbacks, detaching mini-filter devices, and replacing driver major functions.
Categories: vulnerable driver, verified
View authoritative reference β
NeacSafe64.sys
NetEase NeacSafe64.sys is an anti-cheat mini-filter driver referenced by KDU and public NeacController research. Versions prior to 1.0.0.8 expose IOCTL/message-handler paths that provide arbitrary kernel read/write primitives and can be chained for SYSTEM privilege escalation or kernel-mode code execution.
Categories: vulnerable driver, verified
View authoritative reference β
ACE-BASE.sys
Allows privilege escalation from regular user to System or PPL
Categories: vulnerable driver, unverified
View authoritative reference β
sandra.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, verified
View authoritative reference β
RwDrv.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, verified
View authoritative reference β
834761775.sys
Cisco Talos has identified multiple versions of an undocumented malicious driver named βRedDriver,β a driver-based browser hijacker that uses the Windows Filtering Platform (WFP) to intercept browser traffic. RedDriver has been active since at least 2021.
RedDriver utilizes HookSignTool to forge its signature timestamp to bypass Windows driver-signing policies.
Code from multiple open-source tools has been used in the development of RedDriver's infection chain, including HP-Socket and a custom implementation of ReflectiveLoader.
The authors of RedDriver appear to be skilled in driver development and have deep knowledge of the Windows operating system.
This threat appears to target native Chinese speakers, as it searches for Chinese language browsers to hijack. Additionally, the authors are likely Chinese speakers themselves.
Categories: malicious, verified
View authoritative reference β
KExplore.sys
KExplore.sys is Pavel Yosifovich's Kernel Explorer driver and is listed as a KDU-compatible provider. KDU uses supported provider drivers to access kernel memory primitives for actions such as process-object modification and driver mapping.
Categories: vulnerable driver, verified
View authoritative reference β
Proxy32.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, unverified
View authoritative reference β
Black.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, unverified
View authoritative reference β
mtxC9CB.sys
mtxC9CB.sys is a vulnerable kernel driver from the KeServiceDescriptorTable/vulnerable-drivers repository. The driver exposes dangerous kernel primitives to usermode.
Categories: vulnerable driver, verified
View authoritative reference β
TestBone.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, unverified
View authoritative reference β
AsrCDDrv.sys
AsrCDDrv.sys is a kernel driver from ASRock Incorporation that exposes control register read/write (cr0, cr2, cr3, cr4, cr8), arbitrary MSR read/write, arbitrary physical memory read/write via MmMapIoSpace, contiguous memory allocation/free via MmAllocateContiguousMemorySpecifyCache, and I/O port read/write (8/16/32-bit). The driver is available in the KeServiceDescriptorTable/vulnerable-drivers repository.
Categories: vulnerable driver, verified
View authoritative reference β
driver_85ca0dcd.sys
Sophos, from time to time, has observed a threat actor deploy variants of Poortry on different machines within a single estate during an attack. These variants contain the same payload, but signed with a different certificate than the driver first seen used during the attack.
Categories: malicious, verified
View authoritative reference β
winio64.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, verified
View authoritative reference β
GlobalVistaVentures_v3.sys
GlobalVistaVentures_v3.sys is a vulnerable kernel driver from the KeServiceDescriptorTable/vulnerable-drivers repository. The driver exposes dangerous kernel primitives to usermode.
Categories: vulnerable driver, verified
View authoritative reference β
driver_e1123b59.sys
Sophos, from time to time, has observed a threat actor deploy variants of Poortry on different machines within a single estate during an attack. These variants contain the same payload, but signed with a different certificate than the driver first seen used during the attack.
Categories: malicious, verified
View authoritative reference β
PlugPlayService.sys
Nextron Systems identified PlugPlayService.sys as a heavily obfuscated, WHQL-signed malicious Windows kernel driver providing arbitrary memory access and direct access to RAID devices. Nextron catalogs this exact sample as an obfuscated kernel PE loader with arbitrary shellcode execution capabilities. Its embedded signature uses Microsoft Windows Hardware Compatibility Publisher. Nextron reports control-flow obfuscation similarities to RegPhantom and reports that xigmapper has deployed similar drivers; these observations do not establish that this exact sample is RegPhantom or was deployed by a particular xigmapper sample. Static analysis confirms encoded indirect calls, system-thread creation, physical-memory mapping, and enumeration of Disk driver device objects. The neonddu.sys sample has byte-identical PE sections and the same Authentihash as PlugPlayService.sys, but has a different embedded signature that fails cryptographic verification; the WHQL signing observation applies to PlugPlayService.sys, not neonddu.sys.
Categories: malicious, verified
View authoritative reference β
p2KGhmzsARY1.sys
p2KGhmzsARY1.sys is a vulnerable kernel driver from the KeServiceDescriptorTable/vulnerable-drivers repository. The driver exposes dangerous kernel primitives to usermode.
Categories: vulnerable driver, verified
View authoritative reference β
Se64a.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, verified
View authoritative reference β
kdhacker64_ev.sys
kdhacker64_ev.sys is a kernel driver from Beijing Kingsoft Security software bundled with Kingsoft AntiVirus and Liebao Browser. The driver exposes a kernel heap buffer overflow via IOCTL 0x120140 with approximately 512 bytes of overflow into adjacent kernel pool allocations. The root cause is a size validation mismatch -- input is validated at 0x488 bytes per element but only 0x248 bytes are allocated per element. RtlInitUnicodeString is called on user-controlled buffers without null terminator bounds checking, producing oversized ANSI strings that overflow 64-byte destination buffers. No authentication is required to access the device. The driver also includes TDI hooks for TCP/UDP/RawIP interception, process creation notification callbacks, filesystem filter attachments to NTFS/FAT/CDFS, camera device monitoring, and HTTP header parsing. Other Kingsoft drivers (ksapi.sys, mydrivers.sys) are already tracked in LOLDrivers.
Categories: vulnerable driver, verified
View authoritative reference β
procexp.Sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, verified
View authoritative reference β
WinFlash64.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, verified
View authoritative reference β
b3.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, unverified
View authoritative reference β
Phymemx64.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, verified
View authoritative reference β
SANDRA.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, verified
View authoritative reference β
otipcibus.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, unverified
View authoritative reference β
winio64.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, verified
View authoritative reference β
AsrRapidStartDrv.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, verified
View authoritative reference β
AsrDrv.sys
Confirmed vulnerable driver from Microsoft Block List
Categories: vulnerable driver, verified
View authoritative reference β
test2.sys
Confirmed vulnerable driver from Microsoft Block List
Categories: vulnerable driver, verified
View authoritative reference β
iOCdrv.sys
iOCdrv.sys is a vulnerable kernel driver from the KeServiceDescriptorTable/vulnerable-drivers repository. The driver exposes dangerous kernel primitives to usermode.
Categories: vulnerable driver, verified
View authoritative reference β
MsIo64.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, verified
View authoritative reference β
AsrDrv106.sys
ASRock AsrDrv106 drivers expose physical-memory mapping, contiguous memory allocation, and port-I/O primitives through user-controlled IOCTL handlers, enabling privileged manipulation of kernel memory.
Categories: vulnerable driver, verified
View authoritative reference β
pchunter.sys
Confirmed vulnerable driver from Microsoft Block List
Categories: vulnerable driver, verified
View authoritative reference β
BlackBoneDrv10.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, unverified
View authoritative reference β
BiosToolCommonDriver.sys
BiosToolCommonDriver.sys is an AMD RPMC (Replay Protected Monotonic Counter) field fusing utility driver that exposes 18 IOCTLs including arbitrary physical memory read/write via MmMapIoSpace, unrestricted port I/O, PCI configuration space read/write, MSR read/write (wrmsr/rdmsr), SPI flash read, CPUID execution, virtual-to-physical address translation via MmGetPhysicalAddress, and contiguous memory allocation. WHQL Microsoft-signed and also AMD Sectigo dual-signed. Ships inside Razer Blade 16 BIOS update packages and ASUS firmware config bundles. PDB path confirms AMD internal build origin.
Categories: vulnerable driver, verified
View authoritative reference β
Netfilter.sys
Confirmed vulnerable driver from Microsoft Block List
Categories: vulnerable driver, verified
View authoritative reference β
directio64.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, verified
View authoritative reference β
Cndom6.sys
Signed malicious drivers reported in Silver Fox activity; rwdriver.sys exposes a rootkit IOCTL primitive, while Cndom6.sys and XiaoH.sys are reported as watchdog/support drivers.
Categories: malicious, verified
View authoritative reference β
kernel_utility_driver64.sys
Huorong Security identified these WHCP-signed kernel drivers in Vaultify rogueware. After a challenge-response exchange, the driver accepts a target driver name and removes process-creation callbacks registered by that driver. This strips callback-based antivirus and EDR visibility from kernel context. Public analysis reproduced the behavior in both the 32-bit and 64-bit builds.
Categories: malicious, verified
View authoritative reference β
ampa.sys
Northwave Cyber Security contributed this driver based on in-house research. The driver has a CVSSv3 score of 8.8, indicating a privilege escalation impact. This vulnerability could potentially be exploited for privilege escalation or other malicious activities.
Categories: vulnerable driver, verified
View authoritative reference β
HpPortIox64.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, verified
View authoritative reference β
DriversCloud_amd64.sys
CYBELSOFT DriversCloud_amd64.sys exposes 7 IOCTLs with no access checks and a zero security descriptor on the device object, meaning any user (including low-integrity processes) can open a handle. Primitives include arbitrary physical memory read via MmMapIoSpace (up to 2MB per call), arbitrary MSR read/write (including IA32_LSTAR for instant kernel code execution), arbitrary I/O port read/write, and arbitrary PCI configuration space read/write. A full LSTAR hijack PoC with crash-safe ROP restore has been demonstrated. The developer acknowledged the issue and is working on a rewritten driver.
Categories: vulnerable driver, verified
View authoritative reference β
idmtdi.sys
Sophos, from time to time, has observed a threat actor deploy variants of Poortry on different machines within a single estate during an attack. These variants contain the same payload, but signed with a different certificate than the driver first seen used during the attack.
Categories: malicious, verified
View authoritative reference β
libnicm.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, verified
View authoritative reference β
PoisonX.sys
A Microsoft-signed vulnerable driver used in BYOVD attacks to terminate protected processes, including EDR solutions such as CrowdStrike Falcon. The driver exposes an IOCTL that allows arbitrary process termination from user mode by passing a PID.
Categories: vulnerable driver, verified
View authoritative reference β
4118b86e490aed091b1a219dba45f332.sys
Cisco Talos has identified multiple versions of an undocumented malicious driver named βRedDriver,β a driver-based browser hijacker that uses the Windows Filtering Platform (WFP) to intercept browser traffic. RedDriver has been active since at least 2021. RedDriver utilizes HookSignTool to forge its signature timestamp to bypass Windows driver-signing policies. Code from multiple open-source tools has been used in the development of RedDriver's infection chain, including HP-Socket and a custom implementation of ReflectiveLoader. The authors of RedDriver appear to be skilled in driver development and have deep knowledge of the Windows operating system. This threat appears to target native Chinese speakers, as it searches for Chinese language browsers to hijack. Additionally, the authors are likely Chinese speakers themselves.
Categories: malicious, verified
View authoritative reference β
fd3b7234419fafc9bdd533f48896ed73_b816c5cd.sys
The criminals signed their AV-killer malware, closely related to one known as BURNTCIGAR, with a legitimate WHCP certificate
Categories: vulnerable driver, verified
View authoritative reference β
QIOMem.sys
QIOMem.sys is the Generic IO & Memory Access driver included with Toshiba and Dynabook password utilities. It binds to ACPI\QCI0701; on systems without that firmware device, the public proof of concept creates a matching software PnP device to trigger loading of an already-installed driver package. Six IOCTLs (0x08012000 through 0x08012014) pass an unvalidated 32-bit physical address to MmMapIoSpace, allowing a low-privileged process to read or write one, two, or four bytes of physical memory below 4 GiB.
Categories: vulnerable driver, verified
View authoritative reference β
nvflash.sys
Confirmed vulnerable driver from Microsoft Block List
Categories: vulnerable driver, verified
View authoritative reference β
windrvr1251.sys
Jungo WinDriver versions 6.0.0 through 16.1.0 are affected by multiple kernel security issues fixed in version 16.2.0. The tracked 12.5.1 through 14.1.1 builds fall inside that affected interval. CVE-2024-26314 allows a low-privileged local attacker to escalate privileges and execute arbitrary code. The 14.1.1 driver exposes METHOD_NEITHER requests that reach port I/O, PCI configuration, and mapped-resource operations after the required WinDriver registration workflow.
Categories: vulnerable driver, verified
View authoritative reference β
ADRMDRVSYS.sys
ADLINK Resource Manager exposes physical-memory mapping through IOCTL 0x2234D4, allowing low-privilege callers to read kernel memory. The interface has also been weaponized by Blackout Reloaded to terminate protected antimalware processes through a driver path that reaches ZwTerminateProcess.
Categories: vulnerable driver, verified
View authoritative reference β
atillk64.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, verified
View authoritative reference β
HwRwDrv.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, verified
View authoritative reference β
DcProtect.sys
bundled with chinese application "DrvCeo" is a set of rootkits. The malicious functionality. prevents registry value writing where the registry key or value includes "dcprotect" or "drvceo". Prevents file deletion if pathname contains "driverdownload", "program files\sysceo", "program files (x86)\sysceo"
Categories: vulnerable driver, verified
View authoritative reference β
ntbios.sys
Driver used in the Daxin malware campaign.
Categories: malicious, verified
View authoritative reference β
CP2X72C.SYS
The Carbon Black Threat Analysis Unit (TAU) discovered 34 unique vulnerable drivers (237 file hashes) accepting firmware access. Six allow kernel memory access. All give full control of the devices to non-admin users. By exploiting the vulnerable drivers, an attacker without the system privilege may erase/alter firmware, and/or elevate privileges. As of the time of writing in October 2023, the filenames of the vulnerable drivers have not been made public until now.
Categories: vulnerable driver, verified
View authoritative reference β
snxpsamd.sys
SUNIX Serial Driver x64 version 10.1.0.0 is affected by CVE-2024-55412. This exact signed build exposes raw I/O-port operations to low-privilege callers through IOCTLs including 0x9C403C04 and 0x9C403C08. An attacker can use the unrestricted port read/write primitives to disclose information, tamper with privileged hardware state, and elevate privileges.
Categories: vulnerable driver, verified
View authoritative reference β
SparkIO.sys
SparkIO.sys is a WHQL-signed kernel driver from Clevo Co. (Taiwan ODM) that ships with Control Center 3.0 and Flexicharger utilities on Clevo-chassis laptops (XMG, Eluktronics, EVOO, Origin PC, System76, Sager, and others). CVE-2022-37415 (CVSS 7.8) documents an out-of-bounds write vulnerability. The driver exposes arbitrary physical memory read via MmMapIoSpace, unrestricted I/O port read/write, arbitrary PCI configuration space read/write, and SMBus/I2C read/write. The device is created with IoCreateDevice (no DACL) and IRP_MJ_CREATE returns STATUS_SUCCESS unconditionally with zero caller validation. A public PoC exists by alfarom256.
Categories: vulnerable driver, verified
View authoritative reference β
PDFWKRNL.sys
The Carbon Black Threat Analysis Unit (TAU) discovered 34 unique vulnerable drivers (237 file hashes) accepting firmware access. Six allow kernel memory access. All give full control of the devices to non-admin users. By exploiting the vulnerable drivers, an attacker without the system privilege may erase/alter firmware, and/or elevate privileges. As of the time of writing in October 2023, the filenames of the vulnerable drivers have not been made public until now.
Categories: vulnerable driver, verified
View authoritative reference β
AsrSetupDrv103.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, verified
View authoritative reference β
bin_intigua_driver64.sys
bin_intigua_driver64.sys is a vulnerable kernel driver from the KeServiceDescriptorTable/vulnerable-drivers repository. The driver exposes dangerous kernel primitives to usermode.
Categories: vulnerable driver, verified
View authoritative reference β
mtxmem.sys
mtxmem.sys is a vulnerable kernel driver from the KeServiceDescriptorTable/vulnerable-drivers repository. The driver exposes dangerous kernel primitives to usermode.
Categories: vulnerable driver, verified
View authoritative reference β
4748696211bd56c2d93c21cab91e82a5.sys
Cisco Talos has identified multiple versions of an undocumented malicious driver named βRedDriver,β a driver-based browser hijacker that uses the Windows Filtering Platform (WFP) to intercept browser traffic. RedDriver has been active since at least 2021. RedDriver utilizes HookSignTool to forge its signature timestamp to bypass Windows driver-signing policies. Code from multiple open-source tools has been used in the development of RedDriver's infection chain, including HP-Socket and a custom implementation of ReflectiveLoader. The authors of RedDriver appear to be skilled in driver development and have deep knowledge of the Windows operating system. This threat appears to target native Chinese speakers, as it searches for Chinese language browsers to hijack. Additionally, the authors are likely Chinese speakers themselves.
Categories: malicious, verified
View authoritative reference β
WinIo64B.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, unverified
View authoritative reference β
gpcidrv64.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, verified
View authoritative reference β
LECOMAx64.sys
LECOMAx64.sys is a signed LECO LECOMA device driver referenced by public PPLShade supported-driver research.
Categories: vulnerable driver, verified
View authoritative reference β
SvIoCtrlx64.sys
SvIoCtrlx64.sys is a vulnerable kernel driver from the KeServiceDescriptorTable/vulnerable-drivers repository. The driver exposes dangerous kernel primitives to usermode.
Categories: vulnerable driver, verified
View authoritative reference β
PanMonFlt.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, unverified
View authoritative reference β
RadHwMgr.sys
The Carbon Black Threat Analysis Unit (TAU) discovered 34 unique vulnerable drivers (237 file hashes) accepting firmware access. Six allow kernel memory access. All give full control of the devices to non-admin users. By exploiting the vulnerable drivers, an attacker without the system privilege may erase/alter firmware, and/or elevate privileges. As of the time of writing in October 2023, the filenames of the vulnerable drivers have not been made public until now.
Categories: vulnerable driver, verified
View authoritative reference β
VBoxMouseNT.sys
Confirmed vulnerable driver from Microsoft Block List
Categories: vulnerable driver, verified
View authoritative reference β
c.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, unverified
View authoritative reference β
zam64.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, verified
View authoritative reference β
80.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, unverified
View authoritative reference β
81.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, unverified
View authoritative reference β
piddrv.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, unverified
View authoritative reference β
rzpnk.sys
A vulnerability exists in the latest version of Razer Synapse (v2.20.15.1104 as of the day of disclosure) which can be leveraged locally by a malicious application to elevate its privileges to those of NT_AUTHORITY\SYSTEM. The vulnerability lies in a specific IOCTL handler in the rzpnk.sys driver that passes a PID specified by the user to ZwOpenProcess. CVE-2017-9769.
Categories: vulnerable driver, verified
View authoritative reference β
927e3aef03a8355d236230cace376b3023480a40c5ac08453c07dab343dd1f11
According to Sophos X-Ops
(Aug 06, 2025), a widely shared EDR-killer toolkit drops/loads a malicious
kernel driver signed with compromised or revoked certificates to disable
endpoint protections. Variants target many vendors, and are commonly
HeartCrypt-packed and used by ransomware groups (e.g., RansomHub, INC).
The payload uses hard-coded driver names (e.g., mraml.sys, noedt.sys) and
kills security services/processes.
Categories: vulnerable driver, verified
View authoritative reference β
amifldrv64.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, verified
View authoritative reference β
driver_290bc782.sys
Sophos, from time to time, has observed a threat actor deploy variants of Poortry on different machines within a single estate during an attack. These variants contain the same payload, but signed with a different certificate than the driver first seen used during the attack.
Categories: malicious, verified
View authoritative reference β
BS_RVSIO64.sys
BS_RVSIO64.sys is a vulnerable kernel driver from the KeServiceDescriptorTable/vulnerable-drivers repository. The driver exposes dangerous kernel primitives to usermode.
Categories: vulnerable driver, verified
View authoritative reference β
STProcessMonitor.sys
Safetica STProcessMonitor / ProcessMonitorDriver.sys exposes process-termination functionality through vulnerable IOCTL paths documented in public BYOVD research. The tracked samples include the 11.26.18.0 build and the legacy 11.11.4.0 build; public research notes that affected versions can be abused to terminate endpoint security processes from kernel context.
Categories: vulnerable driver, verified
View authoritative reference β
IUForceDelete.sys
IUForceDelete.sys is a vulnerable kernel driver from the KeServiceDescriptorTable/vulnerable-drivers repository. The driver exposes dangerous kernel primitives to usermode.
Categories: vulnerable driver, verified
View authoritative reference β
KfeCo10X64.sys
Killer exposes COM interfaces that allow non-privileged users 1) to block network for any process 2) to manage any service in the OS. Killer is preinstalled to laptops equipped with Intel Killer NICs (e.g. Dell). Since Intel patched the vulnerability quietly, it's not clear which version is safe. Also, it is unclear which OEMs are affected. Dell is definitely in the list, but it is likely that other vendors with Killer NICs on board, such as Acer and MSI, are affected too. Some users think that Killer suite is required for the NIC to work properly, so they install it even after a fresh Windows install. This version is confirmed vulnerable based on the script usage from zwclose.
Categories: vulnerable driver, verified
View authoritative reference β
ProxyDrv.sys
Confirmed vulnerable driver from Microsoft Block List
Categories: vulnerable driver, verified
View authoritative reference β
HwOs2Ec7x64.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, verified
View authoritative reference β
portwell.sys
portwell.sys is a kernel driver from Portwell Inc. (Taiwan) that exposes physical memory read/write via MmMapIoSpace. Portwell manufactures embedded computing platforms and industrial PCs. The driver is available in the KeServiceDescriptorTable/vulnerable-drivers repository.
Categories: vulnerable driver, verified
View authoritative reference β
jnprva.sys
Northwave Cyber Security contributed this driver based on in-house research. The driver has a CVSSv3 score of 8.8, indicating a privilege escalation impact. This vulnerability could potentially be exploited for privilege escalation or other malicious activities.
Categories: vulnerable driver, verified
View authoritative reference β
ktmutil7ODM.sys
Cisco Talos has identified multiple versions of an undocumented malicious driver named βRedDriver,β a driver-based browser hijacker that uses the Windows Filtering Platform (WFP) to intercept browser traffic. RedDriver has been active since at least 2021.
RedDriver utilizes HookSignTool to forge its signature timestamp to bypass Windows driver-signing policies.
Code from multiple open-source tools has been used in the development of RedDriver's infection chain, including HP-Socket and a custom implementation of ReflectiveLoader.
The authors of RedDriver appear to be skilled in driver development and have deep knowledge of the Windows operating system.
This threat appears to target native Chinese speakers, as it searches for Chinese language browsers to hijack. Additionally, the authors are likely Chinese speakers themselves.
Categories: malicious, verified
View authoritative reference β
Monitor_win10_x64.sys
CVE-2018-16712
Categories: vulnerable driver, verified
View authoritative reference β
driver7-x86.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, verified
View authoritative reference β
t3.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, unverified
View authoritative reference β
hw.sys
Northwave Cyber Security contributed this driver based on in-house research. The driver has a CVSSv3 score of 8.8, indicating a privilege escalation impact. This vulnerability could potentially be exploited for privilege escalation or other malicious activities.
Categories: vulnerable driver, verified
View authoritative reference β
chinese_cheat_driver.sys
chinese_cheat_driver.sys is a vulnerable kernel driver from the KeServiceDescriptorTable/vulnerable-drivers repository. The driver exposes dangerous kernel primitives to usermode. Public exploit research documents IOCTL 0x222000 for arbitrary kernel virtual memory reads, IOCTL 0x222018 for physical memory reads, and IOCTL 0x22201C for physical memory writes, which can be chained for local privilege escalation from an administrator context to NT AUTHORITY\SYSTEM.
Categories: vulnerable driver, verified
View authoritative reference β
Novawave_Novabench_NovabenchDriverWin10.sys
Novawave_Novabench_NovabenchDriverWin10.sys is a vulnerable kernel driver from the KeServiceDescriptorTable/vulnerable-drivers repository. The driver exposes dangerous kernel primitives to usermode.
Categories: vulnerable driver, verified
View authoritative reference β
fidpcidrv64.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, verified
View authoritative reference β
Lurker.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, unverified
View authoritative reference β
BdApiUtil.sys
Driver can be used to load unsigned drivers. IOCTL code which takes a PID and terminates it (arbitrary process termination). Admin privileges required to install the driver, but if it's already installed, can be called by any user (non admin).
Categories: vulnerable driver, verified
View authoritative reference β
driver_930da474.sys
Sophos, from time to time, has observed a threat actor deploy variants of Poortry on different machines within a single estate during an attack. These variants contain the same payload, but signed with a different certificate than the driver first seen used during the attack.
Categories: malicious, verified
View authoritative reference β
Mhyprot2.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, verified
View authoritative reference β
dellbios.sys
The Carbon Black Threat Analysis Unit (TAU) discovered 34 unique vulnerable drivers (237 file hashes) accepting firmware access. Six allow kernel memory access. All give full control of the devices to non-admin users. By exploiting the vulnerable drivers, an attacker without the system privilege may erase/alter firmware, and/or elevate privileges. As of the time of writing in October 2023, the filenames of the vulnerable drivers have not been made public until now.
Categories: vulnerable driver, verified
View authoritative reference β
CSC.sys
Improper Address Validation in IOCTL with METHOD_NEITHER I/O Control Code in the csc.sys driver
Categories: vulnerable driver, verified
View authoritative reference β
SIOCTL.sys
SIOCTL.sys is a vulnerable kernel driver from the KeServiceDescriptorTable/vulnerable-drivers repository. The driver exposes dangerous kernel primitives to usermode.
Categories: vulnerable driver, verified
View authoritative reference β
b4.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, unverified
View authoritative reference β
WiRwaDrv.sys
The Carbon Black Threat Analysis Unit (TAU) discovered 34 unique vulnerable drivers (237 file hashes) accepting firmware access. Six allow kernel memory access. All give full control of the devices to non-admin users. By exploiting the vulnerable drivers, an attacker without the system privilege may erase/alter firmware, and/or elevate privileges. As of the time of writing in October 2023, the filenames of the vulnerable drivers have not been made public until now.
Categories: vulnerable driver, verified
View authoritative reference β
RzDev_00X10.sys
Nextron Systems identifies this exact sample as a kernel communication and memory-access component with a covert user-to-kernel channel and privileged memory read/write. Static analysis confirms MDL-backed kernel mappings and a transfer path that probes a caller buffer and maps supplied virtual ranges in page-sized chunks. The obfuscated transfer callback was not fully resolved; the covert channel and privileged memory read/write semantics are source-reported, not independently demonstrated. The observed RzDev_00X10.sys filename does not establish vendor ownership.
Categories: malicious, verified
View authoritative reference β
cyvrlpc.sys
Per Sophos X-Ops research
(Aug 06, 2025), threat actors deploy an EDR-killer that loads a malicious
kernel driver (often with a random five-letter name) signed with
compromised or revoked code-signing certificates (e.g., Changsha Hengxiang
Information Technology; Fuzhou Dingxin Trade). The tool targets many
security products by killing their services and processes and is frequently
distributed packed with HeartCrypt by ransomware groups (e.g., RansomHub,
INC). Driver names are hard-coded per sample (e.g., mraml.sys, noedt.sys).
Categories: vulnerable driver, verified
View authoritative reference β
directio.sys
Confirmed vulnerable driver from Microsoft Block List
Categories: vulnerable driver, verified
View authoritative reference β
POORTRY.sys
Driver categorized as POORTRY by Mandiant.
Categories: malicious, verified
View authoritative reference β
capcom.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, verified
View authoritative reference β
RootLaser.sys
Adlice RootLaser.sys version 3.4.1 is a signed kernel driver with administrator-reachable kernel read and write primitives through IOCTLs 0x22E050 and 0x22E014. Public proof-of-concept code combines these primitives with build-specific kernel offsets to replace a process token and elevate an administrator to SYSTEM. The exploit requires offsets that match the target Windows build.
Categories: vulnerable driver, verified
View authoritative reference β
LgCoreTemp.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, verified
View authoritative reference β
deresute64.sys
Create and start driver
Categories: vulnerable driver, verified
View authoritative reference β
mst.sys
mst.sys is a vulnerable kernel driver from the KeServiceDescriptorTable/vulnerable-drivers repository. The driver exposes dangerous kernel primitives to usermode.
Categories: vulnerable driver, verified
View authoritative reference β
AdvCare.sys
AdvCare.sys is a legacy hardware health monitor driver from Advantech Co., Ltd. for industrial PCs and embedded boards. The driver exposes arbitrary MSR read/write (wrmsr/rdmsr with no validation), arbitrary physical memory read/write via MmMapIoSpace, unrestricted port I/O across all 65536 ports, and PCI configuration space read/write via HalGetBusDataByOffset/HalSetBusDataByOffset. The device is created with IoCreateDevice (no DACL) and IRP_MJ_CREATE returns STATUS_SUCCESS unconditionally with zero caller validation -- no admin check, no token check, no integrity check. Any unprivileged local user can open the device and invoke every primitive. The driver is also available in the KeServiceDescriptorTable/vulnerable-drivers repository on GitHub.
Categories: vulnerable driver, verified
View authoritative reference β
tm_filter.sys
Teramind Inc. kernel-mode filter drivers (tm_filter.sys and tmfsdrv2.sys) providing kernel-level input capture including keylogging and screen capture capabilities. Both signed by DigiCert under Teramind Inc. certificate. Execution parents point to teramind_agent MSI installer. Abused by threat actors for stealth monitoring operations. tmfsdrv2.sys has 1/73 detections on VirusTotal.
Categories: vulnerable driver, verified
View authoritative reference β
mhyprotrpg.sys
Confirmed vulnerable driver from Microsoft Block List
Categories: vulnerable driver, verified
View authoritative reference β
hw.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, verified
View authoritative reference β
OAToolx64.sys
OAToolx64.sys is a vulnerable kernel driver from the KeServiceDescriptorTable/vulnerable-drivers repository. The driver exposes dangerous kernel primitives to usermode.
Categories: vulnerable driver, verified
View authoritative reference β
HWAuidoOs2Ec.sys
Huawei HWAuidoOs2Ec.sys is a vulnerable kernel driver from public vulnerable-driver research. Public DragonForce reporting also lists this driver in BYOVD tradecraft used to disable endpoint security tooling.
Categories: vulnerable driver, verified
View authoritative reference β
ktapi.sys
ktapi.sys is a legacy cross-signed Kontron Technology Application Programming Interface driver that exposes the \\.\ktapi device to user mode. IOCTL 0x82007000 accepts a caller-controlled interface type, bus address, and size before using HalTranslateBusAddress, ZwOpenSection, and ZwMapViewOfSection to map physical memory into the calling process. Certain interface types cause HalTranslateBusAddress to return the supplied address unchanged, allowing an attacker to map arbitrary system RAM for physical-memory read and write. Expel documented this primitive in an EDR-killer exploit used by The Gentlemen ransomware group to obtain kernel code execution and terminate security processes.
Categories: vulnerable driver, verified
View authoritative reference β
PCTcore64.sys
PC Tools PCTcore64.sys is documented by BlackSnufkin BYOVD research and CERT/CC as CVE-2026-8501. The driver creates a PCTCore device interface without restrictive access controls and exposes a process-termination IOCTL reachable by local callers.
Categories: vulnerable driver, verified
View authoritative reference β
mhyprot3.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, verified
View authoritative reference β
driver_5c308aed.sys
Sophos, from time to time, has observed a threat actor deploy variants of Poortry on different machines within a single estate during an attack. These variants contain the same payload, but signed with a different certificate than the driver first seen used during the attack.
Categories: malicious, verified
View authoritative reference β
WiseUnlo.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, verified
View authoritative reference β
ene.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, verified
View authoritative reference β
CmUpx.sys
CmUpx.sys is a vulnerable kernel driver from the KeServiceDescriptorTable/vulnerable-drivers repository. The driver exposes dangerous kernel primitives to usermode.
Categories: vulnerable driver, verified
View authoritative reference β
AppVkgr.sys
AppVkgr.sys is a vulnerable kernel driver from the KeServiceDescriptorTable/vulnerable-drivers repository. The driver exposes dangerous kernel primitives to usermode.
Categories: vulnerable driver, verified
View authoritative reference β
kEvP64.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, verified
View authoritative reference β
driver_16773074.sys
Sophos, from time to time, has observed a threat actor deploy variants of Poortry on different machines within a single estate during an attack. These variants contain the same payload, but signed with a different certificate than the driver first seen used during the attack.
Categories: malicious, verified
View authoritative reference β
termdd.sys
A vulnerable kernel driver that can be used to disable Code Integrity
Categories: vulnerable driver, verified
View authoritative reference β
cg6kwin2k.sys
Sangoma cg6kwin2k versions before 2.1.7.0 expose IOCTLs without sufficient access control. A low-privilege user can perform I/O against arbitrary hardware ports or physical addresses, enabling firmware erasure or modification.
Categories: vulnerable driver, verified
View authoritative reference β
driver_1afc1d06.sys
Sophos, from time to time, has observed a threat actor deploy variants of Poortry on different machines within a single estate during an attack. These variants contain the same payload, but signed with a different certificate than the driver first seen used during the attack.
Categories: malicious, verified
View authoritative reference β
WDTKernel.sys
WDTKernel.sys is a Dell Watchdog Timer Kernel Driver that exposes 12 IOCTLs for arbitrary physical memory read/write via MmMapIoSpace with zero validation on user-supplied physical addresses. It also provides 12 IOCTLs for unrestricted I/O port access and 2 IOCTLs for PCI configuration space access. The driver was WHQL attestation signed through Microsoft and is distributed via the Microsoft Update Catalog. VMware Carbon Black TAU mentioned this driver in their October 2023 research but classified it as not vulnerable in terms of access control because its INF sets an SDDL restricting device access to Administrators and SYSTEM. The arbitrary physical memory R/W via MmMapIoSpace was not analyzed or documented by TAU. Device path is \\.\__WDT__. Suitable for BYOVD attacks where the attacker already has admin privileges and needs kernel-level memory access to bypass EDR.
Categories: vulnerable driver, verified
View authoritative reference β
kt2.sys
BlackCat Ransomware Deploys New Signed Kernel Driver. BlackCat ransomware incident that occurred in February 2023.
Categories: malicious, unverified
View authoritative reference β
NodeDriver.sys
Driver categorized as POORTRY by Mandiant.
Categories: malicious, verified
View authoritative reference β
atidsmxx.sys
AMD's ATI DSM Dynamic Driver exposes hardware-control IOCTLs through \Device\AtiDCM. The interface accepts caller-controlled MSR indexes for RDMSR operations and exposes PCI/device I/O and physical-address mapping paths. These privileged primitives can disclose hardware state and support kernel-level tampering when the device is accessible from user mode.
Categories: vulnerable driver, verified
View authoritative reference β
psmounterex.sys
Northwave Cyber Security contributed this driver based on in-house research. The driver has a CVSSv3 score of 8.8, indicating a privelege escalation impact. This vulnerability could potentially be exploited for privilege escalation or other malicious activities.
Categories: vulnerable driver, verified
View authoritative reference β
driver_099ef491.sys
Sophos, from time to time, has observed a threat actor deploy variants of Poortry on different machines within a single estate during an attack. These variants contain the same payload, but signed with a different certificate than the driver first seen used during the attack.
Categories: malicious, verified
View authoritative reference β
DCRCVDrv.sys
DCRCVDrv.sys exposes IOCTL 0x2205C0 which allows user-mode applications to terminate arbitrary processes from the kernel via ZwTerminateProcess. The IOCTL input buffer contains the PID to terminate. Abused by the Cruciferra MaaS loader, which writes the driver to C:\Windows\Temp\DCRCVDrv.sys, creates a service for it, and opens a handle via the symbolic link \\.\DCRCVDRV_U to kill AV/EDR processes.
Categories: vulnerable driver, verified
View authoritative reference β
K7RKScan.sys
Driver can be used to load unsigned drivers
Categories: vulnerable driver, verified
View authoritative reference β
AsusSAIO.sys
ASUS System Analysis IO release lines before 1.0.30.0 and before 3.1.41.0 are affected by CVE-2024-55408. The tracked 1.0.1.0 through 1.0.9.0 builds fall inside the affected 1.x line and expose FILE_ANY_ACCESS platform-control IOCTLs through the \Device\AsusSAIO interface. Capabilities vary by build and include PCI-derived MMIO, SMBus, I/O-port, and model-specific register operations without a caller-token authorization gate, allowing local callers to misuse privileged hardware controls.
Categories: vulnerable driver, verified
View authoritative reference β
NGStar.sys
NGStar.sys is the kernel-mode USB fingerprint sensor driver for NITGEN Fingkey Hamster II/III devices. The driver creates \Device\gstar-0 exposed as \\.\gstar-0 via IoCreateDevice with FILE_DEVICE_UNKNOWN and no IoCreateDeviceSecure call, making all 28 IOCTL codes (0x00222004-0x00222070) reachable by any unprivileged user-mode process (FILE_ANY_ACCESS on all codes). IOCTLs 0x0022206C and 0x00222070 allocate a fixed 10-byte NonPagedPool block via the deprecated ExAllocatePool API then pass it directly as the receive buffer for an uncapped USB bulk transfer with no post-transfer bounds check β kernel pool overflow leading to local privilege escalation to SYSTEM. ExAllocatePool (non-tagged, removed from Windows 11 and Server 2022 kernel exports) causes a kernel bugcheck (BSOD) on any IOCTL reaching the allocation path β confirmed local DoS. IOCTL 0x00222050 decrements a session reference counter at [rbp+0x40] via lock add without an underflow guard; counter wraps to 0xFFFFFFFF from zero, corrupting the device extension refcount and triggering premature cleanup leading to use-after-free. Driver carries no embedded PE signature; trusted via catalog fdu11.cat (VeriSign-signed, expired 2014, valid via timestamp countersignature). VT detection: 0/77.
Categories: vulnerable driver, verified
View authoritative reference β
BSMEM64_W10.sys
Biostar BSMEM64_W10 exposes direct physical-memory and port/PCI access through \Device\BSMEM. IOCTLs 0x226044 and 0x226084 map caller-selected physical addresses with MmMapIoSpace and copy data from or to the mapped region, providing arbitrary physical-memory read and write primitives.
Categories: vulnerable driver, verified
View authoritative reference β
nicm.sys
nicm.sys is a vulnerable driver. CVE-2013-3956.
Categories: vulnerable driver, verified
View authoritative reference β
NTIOLib.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, verified
View authoritative reference β
PanMonFltX64.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, unverified
View authoritative reference β
amsdk.sys
Vulnerable driver found in https://github.com/hfiref0x/KDU.
Categories: vulnerable driver, verified
View authoritative reference β
bootrepair.sys
BootRepair.sys is a legitimate Lenovo kernel driver shipped with Lenovo PC Manager (signed by LENOVO via Symantec Class 3 SHA256 Code Signing CA, compile date 2018-01-03). The driver creates a device object at \\.\BootRepair with no DACL restrictions, so any local user can open a handle. The IRP_MJ_DEVICE_CONTROL dispatcher accepts IOCTL 0x222014 with a 4-byte DWORD input (target PID) and chains PsLookupProcessByProcessId -> ObOpenObjectByPointer -> ZwTerminateProcess against the supplied PID, with no caller validation. Because the kernel-mode caller bypasses user-mode access checks, the primitive can terminate any process on the system including PPL-protected AV/EDR processes. The driver also imports ZwCreateKey / ZwSetValueKey / ZwQueryValueKey (registry access for the boot-repair feature), PsCreateSystemThread / IoRegisterShutdownNotification, and KeBugCheckEx.
Categories: vulnerable driver, verified
View authoritative reference β
sfdrvx32.sys
Confirmed vulnerable driver from Microsoft Block List
Categories: vulnerable driver, verified
View authoritative reference β
K7RKScan.sys
Driver can be used to load unsigned drivers
Categories: vulnerable driver, verified
View authoritative reference β
sxav64-v1.5.1.sys
The signed SXClient sxav.sys security driver processes an SXBOOTDB boot configuration whose integrity is protected only by an unkeyed MD5 digest. Public research demonstrates that an administrator can generate a valid configuration containing arbitrary absolute paths, point the service to it, and have the kernel driver delete those files during the next boot. The primitive can be abused to remove security-product files that are otherwise locked while Windows is running.
Categories: vulnerable driver, verified
View authoritative reference β
mydrivers.sys
DriverGenius mydrivers.sys 9.2.707.1214 is affected by CVE-2023-1676. IOCTL 0x9C402088 dispatches caller-controlled values to the privileged WRMSR instruction without adequate access control. A local user can corrupt kernel state, execute code in ring 0, and elevate privileges.
Categories: vulnerable driver, verified
View authoritative reference β
iomem64.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, verified
View authoritative reference β
t8.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, unverified
View authoritative reference β
directio64.sys
PassMark DirectIo64.sys builds through b1008 expose permissively accessible IOCTLs for physical memory, MSRs, PCI configuration space, x86 I/O ports, and kernel or physical-memory dumps. These primitives can support local SYSTEM elevation, kernel tampering, credential exposure, or denial of service. PassMark hardened the driver in b1012.
Categories: vulnerable driver, verified
View authoritative reference β
xhunter1.sys
Wellbia xhunter1.sys is an XIGNCODE3 anti-cheat kernel component affected by CVE-2026-3609 through version 2023.12.7.78. Public research demonstrates that its unauthenticated command channel can expose protected-process handles, read cross-process memory, terminate security processes, elevate privileges, and inject code from kernel context.
Categories: vulnerable driver, verified
View authoritative reference β
thelper.sys
OCular THelper driver with arbitrary kernel memory read/write and process manipulation capabilities. Identified in ESET EDR killers research (March 2026) with 46 execution parents linked to AgentStp campaigns abusing the driver to disable EDR products.
Categories: vulnerable driver, verified
View authoritative reference β
PanIOx64.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, unverified
View authoritative reference β
WinTapix.sys
Wintapix.sys is partially protected by VMProtect, a software protection tool that uses virtualization to protect software applications from reverse engineering and unauthorized usage. It transforms the original executable file into a virtualized code executed in a protected environment, making it difficult to analyze and tamper with.
Categories: malicious, verified
View authoritative reference β
Blackbone.sys
Confirmed vulnerable driver from Microsoft Block List
Categories: vulnerable driver, verified
View authoritative reference β
zntport.sys
The legacy NTPort driver creates the "\\.\zntport" device and exposes IOCTL 0xF10024CC with FILE_ANY_ACCESS. The handler accepts a caller-controlled 32-bit physical address, maps 0x32 bytes below 4 GiB with MmMapIoSpace, and copies data through an unchecked strcpy operation. After an administrator installs the driver, an unprivileged process may be able to abuse the device for physical-memory disclosure or memory corruption, depending on the device ACL.
Categories: vulnerable driver, verified
View authoritative reference β
MemCtl.sys
MemCtl.sys is a vulnerable kernel driver from the KeServiceDescriptorTable/vulnerable-drivers repository. The driver exposes dangerous kernel primitives to usermode.
Categories: vulnerable driver, verified
View authoritative reference β
irec.sys
The driver in question, identified as \\.\IREC, provides an interface for external programs to directly interact with system processes. Its key functionality is encapsulated in the OPENPROCESS function which, upon receiving a Process ID (PID), returns a handle to that specific process operating within the kernels domain. The vulnerability emerges from the indiscriminate nature of this functionality. An ill-intentioned actor can exploit this to obtain handles to critical processes like LSASS. With a hardcoded access mask of 0x410, this driver essentially grants PROCESS_QUERY_INFORMATION and PROCESS_VM_READ permissions, enabling unauthorized memory dumps from privileged processes, all from an unprivileged context.
Categories: vulnerable driver, verified
View authoritative reference β
AsrDrv10.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, verified
View authoritative reference β
BioNTdrv.sys
Paragon Hard Disk Manager BioNTdrv.sys versions 10.1.x and older, 1.0.0.0, 1.1.0.0, 1.3.0.0, 1.4.0.0, and 1.5.1.0 contain five vulnerabilities that expose arbitrary kernel-memory mapping, write, and move operations, insecure kernel resource access, and a null-pointer dereference. Local attackers can use the affected driver to elevate to SYSTEM or cause a denial of service. CVE-2025-0289 has been observed in ransomware BYOVD attacks. Version 2.0.0 fixes the flaws.
Categories: vulnerable driver, verified
View authoritative reference β
Lv561av.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, unverified
View authoritative reference β
Alinubx.sys
Alinubx.sys exposes IOCTL 0x222024 which allows user-mode applications to terminate arbitrary processes from the kernel via ZwTerminateProcess. The IOCTL input buffer expects a structure containing the PID (DWORD) and an exit status code (DWORD). Abused by the Cruciferra MaaS loader to kill AV/EDR processes.
Categories: vulnerable driver, verified
View authoritative reference β
5a4fe297c7d42539303137b6d75b150d.sys
Cisco Talos has identified multiple versions of an undocumented malicious driver named βRedDriver,β a driver-based browser hijacker that uses the Windows Filtering Platform (WFP) to intercept browser traffic. RedDriver has been active since at least 2021. RedDriver utilizes HookSignTool to forge its signature timestamp to bypass Windows driver-signing policies. Code from multiple open-source tools has been used in the development of RedDriver's infection chain, including HP-Socket and a custom implementation of ReflectiveLoader. The authors of RedDriver appear to be skilled in driver development and have deep knowledge of the Windows operating system. This threat appears to target native Chinese speakers, as it searches for Chinese language browsers to hijack. Additionally, the authors are likely Chinese speakers themselves.
Categories: malicious, verified
View authoritative reference β
wantd_4.sys
Driver used in the Daxin malware campaign.
Categories: malicious, verified
View authoritative reference β
tfbfs3ped.sys
Confirmed vulnerable driver from Microsoft Block List
Categories: vulnerable driver, verified
View authoritative reference β
GoFly64.sys
GoFly64.sys is a WFP (Windows Filtering Platform) network filter driver signed by a Chinese software company (εδΊ¬ε²θ¨ηΏη½η»η§ζζιε
¬εΈ / Nanjing Siyanrui Network Technology) that exposes 20+ IOCTLs to usermode with no authentication. The most critical primitive is IOCTL 0x12227A which opens any process by PID via ZwOpenProcess and terminates it via ZwTerminateProcess, enabling kernel-level EDR/AV process killing. Additional capabilities include WFP-based network traffic interception and packet injection (FwpsInjectNetworkSendAsync, FwpsInjectNetworkReceiveAsync), IPv4 traffic redirection (IOCTL 0x122262 via RtlIpv4StringToAddressA), process creation monitoring (PsSetCreateProcessNotifyRoutineEx), image load monitoring (PsSetLoadImageNotifyRoutine), and kernel-mode file write operations. VT shows 88 malicious execution parents including malware droppers and PowerShell scripts, confirming heavy abuse in the wild for BYOVD attacks. Also distributed as PandaSpeed64.sys and drv_02581.sys.
Categories: vulnerable driver, verified
View authoritative reference β
FoxKeDriver64.sys
FoxKeDriver64.sys is a vulnerable Foxconn kernel driver that exposes a \\.\Fox_FOXONE_Driver device. Public research documents IOCTL 0x2220C0 for translating a caller-supplied virtual address to a physical address, which can support local privilege escalation chains with other vulnerable drivers.
Categories: vulnerable driver, verified
View authoritative reference β
ditpio64.sys
ditpio64.sys is a vulnerable kernel driver from the KeServiceDescriptorTable/vulnerable-drivers repository. The driver exposes dangerous kernel primitives to usermode.
Categories: vulnerable driver, verified
View authoritative reference β
mapmom.sys
Confirmed vulnerable driver from Microsoft Block List
Categories: vulnerable driver, verified
View authoritative reference β
iqvw64e.sys
(1) IQVW32.sys before 1.3.1.0 and (2) IQVW64.sys before 1.3.1.0 in the Intel Ethernet diagnostics driver for Windows allows local users to cause a denial of service or possibly execute arbitrary code with kernel privileges via a crafted (a) 0x80862013, (b) 0x8086200B, (c) 0x8086200F, or (d) 0x80862007 IOCTL call.
Categories: vulnerable driver, verified
View authoritative reference β
NICM.sys
Confirmed vulnerable driver from Microsoft Block List
Categories: vulnerable driver, verified
View authoritative reference β
ipctype.sys
ipctype.sys is a kernel driver from Digital Electronics Corporation that exposes physical memory read/write via MmMapIoSpace. The driver is available in the KeServiceDescriptorTable/vulnerable-drivers repository.
Categories: vulnerable driver, verified
View authoritative reference β
AsrDrv107.sys
ASRock AsrDrv107.sys and AsrDrv107n.sys are ASRock IO driver builds listed as KDU providers for ASRock Motherboard Utility versions 3.0.498 and below. The driver family is associated with CVE-2020-15368 and exposes low-level privileged access primitives used by KDU.
Categories: vulnerable driver, verified
View authoritative reference β
energydriver.sys
EnergyDriver.sys is a kernel driver from Intel Corporation shipped with Intel Power Gadget 3.6 (deprecated December 2023). The driver exposes 5 IOCTLs including arbitrary wrmsr (any MSR index, any 64-bit value, no whitelist), arbitrary rdmsr (single CPU or all CPUs), and arbitrary physical memory read via MmMapIoSpace. wrmsr allows IA32_LSTAR hijack for direct syscall redirection. No privilege check, no MSR whitelist, default DACL. WHQL and Intel EV dual-signed.
Categories: vulnerable driver, verified
View authoritative reference β
libnicm.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, verified
View authoritative reference β
ef0e1725aaf0c6c972593f860531a2ea.sys
Cisco Talos has identified multiple versions of an undocumented malicious driver named βRedDriver,β a driver-based browser hijacker that uses the Windows Filtering Platform (WFP) to intercept browser traffic. RedDriver has been active since at least 2021. RedDriver utilizes HookSignTool to forge its signature timestamp to bypass Windows driver-signing policies. Code from multiple open-source tools has been used in the development of RedDriver's infection chain, including HP-Socket and a custom implementation of ReflectiveLoader. The authors of RedDriver appear to be skilled in driver development and have deep knowledge of the Windows operating system. This threat appears to target native Chinese speakers, as it searches for Chinese language browsers to hijack. Additionally, the authors are likely Chinese speakers themselves.
Categories: malicious, verified
View authoritative reference β
t.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, unverified
View authoritative reference β
msio32.sys
Confirmed vulnerable driver from Microsoft Block List
Categories: vulnerable driver, verified
View authoritative reference β
CSAgent.sys
ABYSSWORKER is a malicious driver used in MEDUSA ransomware attacks to disable EDR systems. The driver masquerades as a legitimate CrowdStrike Falcon driver and provides extensive capabilities to terminate processes, remove security callbacks, manipulate files, and disable security tools. It uses stolen certificates from Chinese companies and requires a specific password for activation. The driver was observed being deployed alongside HEARTCRYPT-packed loaders and provides attackers with kernel-level capabilities to blind EDR products by removing notification callbacks, detaching mini-filter devices, and replacing driver major functions.
Categories: vulnerable driver, verified
View authoritative reference β
KApcHelper_x64.sys
Vulnerable driving using the stolen Nvidia Certificate.
Categories: malicious, verified
View authoritative reference β
WinIO32B.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, unverified
View authoritative reference β
dXIw8eZ9aYxQYzgm.sys
dXIw8eZ9aYxQYzgm.sys is a vulnerable kernel driver from the KeServiceDescriptorTable/vulnerable-drivers repository. The driver exposes dangerous kernel primitives to usermode.
Categories: vulnerable driver, verified
View authoritative reference β
d4.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, unverified
View authoritative reference β
kavservice.bin
malicious documented by LOLDrivers.
Categories: malicious, verified
View authoritative reference β
iobitunlocker.sys
Confirmed vulnerable driver from Microsoft Block List
Categories: vulnerable driver, verified
View authoritative reference β
typelibdE.sys
Cisco Talos has identified multiple versions of an undocumented malicious driver named βRedDriver,β a driver-based browser hijacker that uses the Windows Filtering Platform (WFP) to intercept browser traffic. RedDriver has been active since at least 2021.
RedDriver utilizes HookSignTool to forge its signature timestamp to bypass Windows driver-signing policies.
Code from multiple open-source tools has been used in the development of RedDriver's infection chain, including HP-Socket and a custom implementation of ReflectiveLoader.
The authors of RedDriver appear to be skilled in driver development and have deep knowledge of the Windows operating system.
This threat appears to target native Chinese speakers, as it searches for Chinese language browsers to hijack. Additionally, the authors are likely Chinese speakers themselves.
Categories: malicious, verified
View authoritative reference β
NCHGBIOS2x64.SYS
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, verified
View authoritative reference β
stdcdrv64.sys
The Carbon Black Threat Analysis Unit (TAU) discovered 34 unique vulnerable drivers (237 file hashes) accepting firmware access. Six allow kernel memory access. All give full control of the devices to non-admin users. By exploiting the vulnerable drivers, an attacker without the system privilege may erase/alter firmware, and/or elevate privileges. As of the time of writing in October 2023, the filenames of the vulnerable drivers have not been made public until now.
Categories: vulnerable driver, verified
View authoritative reference β
TfSysMon.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, unverified
View authoritative reference β
msrhook.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, verified
View authoritative reference β
WinIo64C.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, unverified
View authoritative reference β
nt5.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, unverified
View authoritative reference β
EneIo64.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, verified
View authoritative reference β
gdrv.sys
gdrv.sys is vulnerable to multiple CVEs: CVE-2018-19320, CVE-2018-19322, CVE-2018-19323, CVE-2018-19321. Read/Write Physical memory, read/write to/from IO ports, exposes ring0 memcpy-like functionality, read and write Machine Specific Registers (MSRs). Affected versions: GIGABYTE APP Center v1.05.21 and previous, AORUS GRAPHICS ENGINE v1.33 and previous, XTREME GAMING ENGINE v1.25 and previous, OC GURU II v2.08
Categories: vulnerable driver, verified
View authoritative reference β
full.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, unverified
View authoritative reference β
daxin_blank1.sys
Driver used in the Daxin malware campaign.
Categories: malicious, verified
View authoritative reference β
HOSTNT.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, verified
View authoritative reference β
phydmaccx86.sys
Confirmed vulnerable driver from Microsoft Block List
Categories: vulnerable driver, verified
View authoritative reference β
malicious.sys
This demo is a presentation at the CYBERSEC 2023 in Taiwan. The presentation showcases the abuse of RTCore64.sys (CVE-2019-16098) from MSI and the nullification of the DSE flag to load a malicious unsigned driver. The presentation also demonstrates an attack on 360 Total Security by nulling out its ObRegisterCallbacks and notify callbacks, enabling the execution of any malicious behavior on the processes of 360 Total Security.
Categories: malicious, verified
View authoritative reference β
aswArPot.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, verified
View authoritative reference β
netfilter2.sys
Confirmed vulnerable driver from Microsoft Block List
Categories: vulnerable driver, verified
View authoritative reference β
HWiNFO64I.SYS
Confirmed vulnerable driver from Microsoft Block List
Categories: vulnerable driver, verified
View authoritative reference β
speedfan.sys
speedfan.sys is a vulnerable driver. CVE-2007-5633.
Categories: vulnerable driver, verified
View authoritative reference β
Afd.sys
Windows Ancillary Function Driver (Afd.sys) for WinSock is vulnerable to an Elevation of Privilege Vulnerability.
Categories: vulnerable driver, verified
View authoritative reference β
driver_ab811ca5.sys
Sophos, from time to time, has observed a threat actor deploy variants of Poortry on different machines within a single estate during an attack. These variants contain the same payload, but signed with a different certificate than the driver first seen used during the attack.
Categories: malicious, verified
View authoritative reference β
KmWpsMs.sys
KmWpsMs.sys is a vulnerable kernel driver from the KeServiceDescriptorTable/vulnerable-drivers repository. The driver exposes dangerous kernel primitives to usermode.
Categories: vulnerable driver, verified
View authoritative reference β
pskmad_64.sys
Panda Kernel Memory Access Driver versions through 1.1.0.21 are affected by CVE-2023-6330, CVE-2023-6331, and CVE-2023-6332. The tracked 1.0.0.16 and 1.0.0.17 builds expose IOCTL 0xB3702C08 through \Device\PSMEMDriver. After a fixed magic value, the request accepts a process, address, and caller-controlled length without relating that length to the fixed buffered-I/O header, allowing kernel-memory disclosure and buffered-output corruption.
Categories: vulnerable driver, verified
View authoritative reference β
a236e7d654cd932b7d11cb604629a2d0.sys
Cisco Talos has identified multiple versions of an undocumented malicious driver named βRedDriver,β a driver-based browser hijacker that uses the Windows Filtering Platform (WFP) to intercept browser traffic. RedDriver has been active since at least 2021. RedDriver utilizes HookSignTool to forge its signature timestamp to bypass Windows driver-signing policies. Code from multiple open-source tools has been used in the development of RedDriver's infection chain, including HP-Socket and a custom implementation of ReflectiveLoader. The authors of RedDriver appear to be skilled in driver development and have deep knowledge of the Windows operating system. This threat appears to target native Chinese speakers, as it searches for Chinese language browsers to hijack. Additionally, the authors are likely Chinese speakers themselves.
Categories: malicious, verified
View authoritative reference β
Windows-Memory-Informer.sys
Windows-Memory-Informer.sys is a vulnerable kernel driver from the KeServiceDescriptorTable/vulnerable-drivers repository. The driver exposes dangerous kernel primitives to usermode.
Categories: vulnerable driver, verified
View authoritative reference β
atlAccess.sys
The Carbon Black Threat Analysis Unit (TAU) discovered 34 unique vulnerable drivers (237 file hashes) accepting firmware access. Six allow kernel memory access. All give full control of the devices to non-admin users. By exploiting the vulnerable drivers, an attacker without the system privilege may erase/alter firmware, and/or elevate privileges. As of the time of writing in October 2023, the filenames of the vulnerable drivers have not been made public until now.
Categories: vulnerable driver, verified
View authoritative reference β
4.sys
SentinelOne has observed prominent threat actors abusing legitimately signed Microsoft drivers in active intrusions into telecommunication, BPO, MSSP, and financial services businesses.
Investigations into these intrusions led to the discovery of POORTRY and STONESTOP malware, part of a small toolkit designed to terminate AV and EDR processes.
We first reported our discovery to Microsoftβs Security Response Center (MSRC) in October 2022 and received an official case number (75361). Today, MSRC released an associated advisory under ADV220005.
This research is being released alongside Mandiant, a SentinelOne technology and incident response partner.
Categories: malicious, verified
View authoritative reference β
cpuz.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, verified
View authoritative reference β
spf.sys
Confirmed vulnerable driver from Microsoft Block List
Categories: vulnerable driver, verified
View authoritative reference β
NPR0.sys
NPR0.sys is a vulnerable kernel driver from the KeServiceDescriptorTable/vulnerable-drivers repository. The driver exposes dangerous kernel primitives to usermode.
Categories: vulnerable driver, verified
View authoritative reference β
burntcigar.sys
BurntCigar (aka POORTRY) is a malicious kernel-mode rootkit driver used by multiple ransomware groups including Cuba, BlackCat, Medusa, LockBit, and RansomHub. Designed to disable and remove EDR solutions by terminating security processes and deleting critical security software files. VMProtect-packed driver signed with stolen Blueone Technology certificate. Detected by 32.9% of AV engines. Facilitates ransomware deployment by rendering systems defenseless.
Categories: malicious, verified
View authoritative reference β
capcom2.sys
Confirmed vulnerable driver from Microsoft Block List
Categories: vulnerable driver, verified
View authoritative reference β
wnbios.sys
Utilized in RealBlindingEDR.
Categories: vulnerable driver, verified
View authoritative reference β
viraglt64.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, verified
View authoritative reference β
fiddrv64.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, verified
View authoritative reference β
ADV64DRV.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, verified
View authoritative reference β
vboxdrv.sys
Used by unknown actor in Acid Rain malware. vboxdrv.sys is a vulnerable driver.
Categories: vulnerable driver, verified
View authoritative reference β
superbmc.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, verified
View authoritative reference β
driver_146b8f4f.sys
Sophos, from time to time, has observed a threat actor deploy variants of Poortry on different machines within a single estate during an attack. These variants contain the same payload, but signed with a different certificate than the driver first seen used during the attack.
Categories: malicious, verified
View authoritative reference β
driver_4fc254af.sys
Sophos, from time to time, has observed a threat actor deploy variants of Poortry on different machines within a single estate during an attack. These variants contain the same payload, but signed with a different certificate than the driver first seen used during the attack.
Categories: malicious, verified
View authoritative reference β
Astra64.sys
ASTRA64.sys is the kernel driver for the ASTRA32 system information tool by Sysinfo Lab (EnTech Taiwan). The driver exposes 31 IOCTLs with zero validation on all parameters including arbitrary physical memory read/write via ZwOpenSection and ZwMapViewOfSection on Device\PhysicalMemory with PAGE_READWRITE, arbitrary port I/O via HalTranslateBusAddress, arbitrary MSR read via rdmsr (enables KASLR bypass via IA32_LSTAR), PCI configuration space read via HalGetBusDataByOffset, and MMIO physical memory mapping via MmMapIoSpace. No authentication gate, no DACL restrictions (plain IoCreateDevice). Loads on any x64 Windows system. EnTech Taiwan also produces TVicPort and softEngine drivers which share similar low-level hardware access patterns. Listed in Eclypsium Screwed-Drivers research.
Categories: vulnerable driver, verified
View authoritative reference β
mimidrv.sys
Mimidrv is a signed Windows Driver Model WDM kernel mode software driver meant to be used with the standard Mimikatz executable.
Categories: malicious, verified
View authoritative reference β
gdrv.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, verified
View authoritative reference β
AsrAutoChkUpdDrv.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, verified
View authoritative reference β
AMDPowerProfiler.sys
AMD uProf AMDPowerProfiler.sys is affected by CVE-2021-26334. Insufficient access control permits lower-privileged callers to access model-specific registers, which can lead to privilege escalation and ring-0 code execution. AMD addresses the issue in the Windows uProf 3.4.494 release.
Categories: vulnerable driver, verified
View authoritative reference β
ElbyCDIO.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, verified
View authoritative reference β
GameDriverX64.sys
GameDriverX64.sys is a signed Hotta Studio anti-cheat driver affected by CVE-2025-61155. Its device-access and IOCTL checks rely on spoofable module names, process names, PE checksums, and the hardcoded value 0xFA123456. A local user can reach kernel routines that terminate arbitrary processes, register a process for handle protection, and strip existing handle rights. KSophon_x64.sys is the VMProtect-packed predecessor shipped with Tower of Fantasy; public reverse engineering reports that it retains the same weak authentication and IOCTL capabilities. The tracked files are legitimate vendor-signed drivers, not malicious drivers, although GameDriverX64.sys has been abused for defense evasion in ransomware intrusions.
Categories: vulnerable driver, verified
View authoritative reference β
xkpsm.sys
xkpsm.sys is an xkeeper kernel driver from JiranJikyosoft. The driver exposes IOCTL 0x8505E008 to user mode and reaches ZwTerminateProcess, enabling kernel-mediated process termination without sufficient caller or target validation. This makes the driver useful in BYOVD-style process termination and security tool impairment scenarios after it is loaded.
Categories: vulnerable driver, verified
View authoritative reference β
iQVW64.SYS
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, verified
View authoritative reference β
driver_fdd16a94.sys
Sophos, from time to time, has observed a threat actor deploy variants of Poortry on different machines within a single estate during an attack. These variants contain the same payload, but signed with a different certificate than the driver first seen used during the attack.
Categories: malicious, verified
View authoritative reference β
d2.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, unverified
View authoritative reference β
MyPortIO_x64.sys
MyPortIO_x64.sys and MyPortIO_x86.sys are Nuvoton Technology kernel drivers bundled with ASRock Polychrome RGB. Public issue #380 and the MyPortIO-Exploit writeup document unauthenticated IOCTL handlers that expose physical memory read/write and I/O port access primitives from user mode.
Categories: vulnerable driver, verified
View authoritative reference β
Windows_CPU_Temperature_Component.sys
Windows_CPU_Temperature_Component.sys is a vulnerable kernel driver from the KeServiceDescriptorTable/vulnerable-drivers repository. The driver exposes dangerous kernel primitives to usermode.
Categories: vulnerable driver, verified
View authoritative reference β
ACPIx86.sys
ABYSSWORKER is a malicious driver used in MEDUSA ransomware attacks to disable EDR systems. The driver masquerades as a legitimate CrowdStrike Falcon driver and provides extensive capabilities to terminate processes, remove security callbacks, manipulate files, and disable security tools. It uses stolen certificates from Chinese companies and requires a specific password for activation. The driver was observed being deployed alongside HEARTCRYPT-packed loaders and provides attackers with kernel-level capabilities to blind EDR products by removing notification callbacks, detaching mini-filter devices, and replacing driver major functions.
Categories: vulnerable driver, verified
View authoritative reference β
sysconp.sys
The Carbon Black Threat Analysis Unit (TAU) discovered 34 unique vulnerable drivers (237 file hashes) accepting firmware access. Six allow kernel memory access. All give full control of the devices to non-admin users. By exploiting the vulnerable drivers, an attacker without the system privilege may erase/alter firmware, and/or elevate privileges. As of the time of writing in October 2023, the filenames of the vulnerable drivers have not been made public until now.
Categories: vulnerable driver, verified
View authoritative reference β
goad.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, unverified
View authoritative reference β
SeasunProtect.sys
Northwave Cyber Security contributed this driver based on in-house research. The driver has a CVSSv3 score of 8.8, indicating a privilege escalation impact. This vulnerability could potentially be exploited for privilege escalation or other malicious activities.
Categories: vulnerable driver, verified
View authoritative reference β
titidrv.sys
Confirmed vulnerable driver from Microsoft Block List
Categories: vulnerable driver, verified
View authoritative reference β
EneTechIo64.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, verified
View authoritative reference β
jokercontroller.sys
Confirmed vulnerable driver from Microsoft Block List
Categories: vulnerable driver, verified
View authoritative reference β
iscflashx64.sys
CVE-2021-33834
Categories: vulnerable driver, verified
View authoritative reference β
gametersafe.sys
Confirmed vulnerable driver from Microsoft Block List
Categories: vulnerable driver, verified
View authoritative reference β
devhost.sys
devhost.sys is a WHQL attestation-signed kernel driver that exposes arbitrary memory read primitives to usermode. The device object at \\.\devhost has no ACL beyond a device handle. At load, the driver reads IA32_LSTAR MSR to locate ntoskrnl base via backward MZ walk, then dynamically resolves APIs (including MmMapIoSpace and MmCopyMemory) using a djb2-style hash algorithm over the PE export directory. Only 11 benign imports are visible statically. The system CR3 is leaked to user-mode at DriverEntry. Authentication uses a hardcoded magic cookie via IOCTL 0x28E017. IOCTL 0x28E01B accepts a caller-supplied CR3 and target virtual address, performs a manual 4-level x64 page-table walk (PML4-PDPT-PD-PT), and reads physical memory via MmMapIoSpace. Additional IOCTLs expose NtBuildNumber, PsLoadedModuleList, and per-CPU KPCR CurrentThread. Nextron Research noted that these primitives are tailor-made for credential theft (e.g. LSASS memory dumping), though no confirmed malicious usage has been publicly documented. WHQL attestation signed with active cert (Nov 2025-Nov 2026). SpcSpOpusInfo identifies the submitter as Shenzhen Aolian Information Security Technology Co Ltd.
Categories: vulnerable driver, verified
View authoritative reference β
BS_RCIO64.sys
BIOSTAR BS_RCIO64_W10 exposes IOCTLs 0x226004 and 0x226008 that map caller-selected physical addresses with MmMapIoSpace and read from or write to the mapped range. Additional IOCTLs expose raw port and PCI configuration access, providing privileged hardware-control primitives suitable for kernel tampering.
Categories: vulnerable driver, verified
View authoritative reference β
shimano32.sys
HyperTech DNP CrackProof DRM kernel drivers (32-bit and 64-bit variants) from Shimano E-TUBE Project. Expose EPROCESS manipulation IOCTLs (0xAA013880, 0xAA013884, 0xAA013888) similar to capcom.sys exploitation technique. Device accessible at \\.\Htsysm4EFB. Zero detections (0/72 and 0/73) on VirusTotal. Signed by Microsoft WHCP via HyperTech DNP CrackProof (Japanese DRM vendor).
Categories: vulnerable driver, verified
View authoritative reference β
My.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, unverified
View authoritative reference β
driver_4d8bc539.sys
Sophos, from time to time, has observed a threat actor deploy variants of Poortry on different machines within a single estate during an attack. These variants contain the same payload, but signed with a different certificate than the driver first seen used during the attack.
Categories: malicious, verified
View authoritative reference β
cpqsysio64.sys
cpqsysio64.sys is a Hewlett-Packard physical-memory driver distributed with ProLiant support and firmware utilities. The tracked 4.5.0.0 and 4.6.0.0 builds handle IOCTL 0x152EF0 by accepting a caller-supplied physical address and length, mapping that range with MmMapIoSpace, and copying from it without constraining the requested physical range. An administrator with device access can read arbitrary physical memory, disclose kernel-sensitive data, and recover addresses that undermine kernel address randomization.
Categories: vulnerable driver, verified
View authoritative reference β
phydmaccx64.sys
Confirmed vulnerable driver from Microsoft Block List
Categories: vulnerable driver, verified
View authoritative reference β
wdisvhost.sys
wdisvhost.sys is a vulnerable kernel driver from the KeServiceDescriptorTable/vulnerable-drivers repository. The driver exposes dangerous kernel primitives to usermode.
Categories: vulnerable driver, verified
View authoritative reference β
ni.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, unverified
View authoritative reference β
rtkio.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, verified
View authoritative reference β
eneio64.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, verified
View authoritative reference β
windows8-10-32.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, unverified
View authoritative reference β
bs_rcio64.sys
Confirmed vulnerable driver from Microsoft Block List
Categories: vulnerable driver, verified
View authoritative reference β
watabe.sys
watabe.sys is a vulnerable kernel driver from the KeServiceDescriptorTable/vulnerable-drivers repository. The driver exposes dangerous kernel primitives to usermode.
Categories: vulnerable driver, verified
View authoritative reference β
nipalk.sys
nipalk.sys is the NI-PAL core kernel driver. The tracked 18.0.0f0 build is within NI-PAL versions before 20.0.1f0 affected by CVE-2021-38304, where improper input validation can allow a local user to escalate privileges. The separately tracked 25.8 build is not attributed to that CVE; exact analysis of that build found physical-memory mapping, virtual-to-physical translation, DMA allocation, bus access, and PCI configuration operations reachable through its IOCTL service gateway.
Categories: vulnerable driver, verified
View authoritative reference β
Agent64.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, verified
View authoritative reference β
prokiller64.sys
Signed POORTRY Samples
Categories: malicious, verified
View authoritative reference β
fastdumpx64.sys
fastdumpx64.sys is a vulnerable kernel driver from the KeServiceDescriptorTable/vulnerable-drivers repository. The driver exposes dangerous kernel primitives to usermode.
Categories: vulnerable driver, verified
View authoritative reference β
pcdsrvc_x64.sys
PC-Doctor pcdsrvc_x64.sys is listed as a KDU provider for Dell PC Doctor / SupportAssist driver abuse. The driver family is associated with CVE-2019-12280 and exposes kernel access primitives used by KDU as a provider for kernel memory operations.
Categories: vulnerable driver, verified
View authoritative reference β
cpuz_x64.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, verified
View authoritative reference β
driver_312c83a9.sys
Sophos, from time to time, has observed a threat actor deploy variants of Poortry on different machines within a single estate during an attack. These variants contain the same payload, but signed with a different certificate than the driver first seen used during the attack.
Categories: malicious, verified
View authoritative reference β
atomicredteamcapcom.sys
Confirmed vulnerable driver from Microsoft Block List
Categories: vulnerable driver, verified
View authoritative reference β
ncpl.sys
ncpl.sys is a vulnerable driver. CVE-2013-3956.
Categories: vulnerable driver, verified
View authoritative reference β
2.sys
Sophos, from time to time, has observed a threat actor deploy variants of Poortry on different machines within a single estate during an attack. These variants contain the same payload, but signed with a different certificate than the driver first seen used during the attack.
Categories: malicious, verified
View authoritative reference β
AIDA64Driver.sys
AIDA64Driver.sys is a vulnerable kernel driver from the KeServiceDescriptorTable/vulnerable-drivers repository. The driver exposes dangerous kernel primitives to usermode.
Categories: vulnerable driver, verified
View authoritative reference β
RTCore64.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, verified
View authoritative reference β
RtsTpx.sys
RtsTpx.sys is a vulnerable kernel driver from the KeServiceDescriptorTable/vulnerable-drivers repository. The driver exposes dangerous kernel primitives to usermode.
Categories: vulnerable driver, verified
View authoritative reference β
Dh_Kernel.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, verified
View authoritative reference β
gameink.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, unverified
View authoritative reference β
daxin_blank.sys
Driver used in the Daxin malware campaign.
Categories: malicious, verified
View authoritative reference β
ampg.sys
Nextron Systems identifies this exact sample as a rootkit combining network interception, obfuscated file operations, and security-product targeting. Observed and embedded filename metadata identify it as ampg.sys. Static analysis confirms WFP filtering and packet-injection paths, XOR-based file transformation, and a process-termination routine explicitly invoked for 360Tray.exe and ZhuDongFangYu.exe. Its embedded version fields claim Microsoft Corporation and SD Crashdump Port Driver; these are file metadata claims, not evidence of Microsoft authorship. No runtime test of successful security-product termination was performed.
Categories: malicious, verified
View authoritative reference β
rtkiow8x64.sys
Confirmed vulnerable driver from Microsoft Block List
Categories: vulnerable driver, verified
View authoritative reference β
HwOs2Ec10x64.sys
Huawei HwOs2Ec 1.0.0.1 exposes kernel process termination to administrative callers. In the tracked HwOs2Ec.sys build, IOCTL 0x22400C accepts a four-byte PID, rejects only PID 0 and PID 4, opens the target with full process access, and calls ZwTerminateProcess. Proofpoint observed this exact signed driver deployed by Cruciferra as an alternative BYOVD helper for tampering with endpoint security tools.
Categories: vulnerable driver, verified
View authoritative reference β
DNDrv.sys
DNDrv.sys is a vulnerable kernel driver from the KeServiceDescriptorTable/vulnerable-drivers repository. The driver exposes dangerous kernel primitives to usermode.
Categories: vulnerable driver, verified
View authoritative reference β
stdcdrvws64.sys
The Carbon Black Threat Analysis Unit (TAU) discovered 34 unique vulnerable drivers (237 file hashes) accepting firmware access. Six allow kernel memory access. All give full control of the devices to non-admin users. By exploiting the vulnerable drivers, an attacker without the system privilege may erase/alter firmware, and/or elevate privileges. As of the time of writing in October 2023, the filenames of the vulnerable drivers have not been made public until now.
Categories: vulnerable driver, verified
View authoritative reference β
driver_bfcbc010.sys
Sophos, from time to time, has observed a threat actor deploy variants of Poortry on different machines within a single estate during an attack. These variants contain the same payload, but signed with a different certificate than the driver first seen used during the attack.
Categories: malicious, verified
View authoritative reference β
blacklotus_driver.sys
The first in-the-wild UEFI bootkit bypassing UEFI Secure Boot on fully updated UEFI systems is now a reality. Once the persistence is configured, the BlackLotus bootkit is executed on every system start. The bootkits goal is to deploy a kernel driver and a final user-mode component.
Categories: malicious, verified
View authoritative reference β
LgDataCatcher.sys
Confirmed vulnerable driver from Microsoft Block List
Categories: vulnerable driver, verified
View authoritative reference β
qu829.sys
Kernel driver signed by "Fuqing Yuntan Network Tech Co.,Ltd." (a revoked VeriSign code-signing certificate that Microsoft has flagged as abused). Multiple samples in this family produce a Cobalt Strike beacon reflective loader YARA hit (Elastic protections-artifacts ruleset Windows_Trojan_CobaltStrike) and are detected by Microsoft as Trojan:Win32/Hitbrovi.G. Samples are dropped to C:\Windows under random eight-character filenames (e.g. qu829.exe) and registered as kernel services. Both observed variants share imphash ca73883db8881686fb258a9d289e3909.
Categories: malicious, verified
View authoritative reference β
fgme.sys
BlackCat Ransomware Deploys New Signed Kernel Driver. BlackCat ransomware incident that occurred in February 2023.
Categories: malicious, unverified
View authoritative reference β
WinIo64.sys
WinIo64 is a hardware-access driver based on the WinIo library that provides direct physical-memory mapping and I/O-port operations from user mode. Its IOCTL interface exposes physical-memory map and unmap, I/O-port read and write, and physical-address translation primitives that are repeatedly incorporated into BYOVD tooling.
Categories: vulnerable driver, verified
View authoritative reference β
pmxdrv64.sys
Intel PMxDrv / pmxdrv64.sys is listed as a KDU provider for Intel Management Engine Tools driver abuse. Public vulnerable-driver research also documents physical-memory access through this driver family.
Categories: vulnerable driver, verified
View authoritative reference β
AppShopDrv103.sys
AppShopDrv103.sys is a hardware utility driver from ASRock distributed with APP Shop and Auto Driver Installer. The driver exposes 30+ IOCTLs through a BCrypt AES-encrypted command wrapper (IOCTL 0x22EC00) with a hardcoded key, providing arbitrary physical memory read and write via MmMapIoSpace (IOCTLs 0x22E808/0x22E80C), unrestricted I/O port read and write in byte, word, and dword widths (IOCTLs 0x22E810-0x22E824), full PCI configuration space read and write via port 0xCF8/0xCFC (IOCTLs 0x22E830-0x22E844), MSR read and write via rdmsr/wrmsr (IOCTLs 0x22E848/0x22E84C), control register reads for CR0/CR2/CR3/CR4/CR8 (IOCTL 0x22E86C), RDTSC and RDPMC performance counter access, CPUID execution, and contiguous memory allocation. Same vulnerability class as other ASRock drivers (AsrDrv.sys) already tracked in LOLDrivers. Used by KDU (Kernel Driver Utility) as a provider.
Categories: vulnerable driver, verified
View authoritative reference β
CSAgent.sys
Sophos X-Ops (Aug 06, 2025)
documents a shared EDR-killer technique where a user-mode loader deploys a
malicious kernel driver signed with compromised/revoked certificates (e.g.,
Changsha Hengxiang Information Technology; Fuzhou Dingxin Trade). The
driver terminates processes/services of multiple security vendors and is
often delivered packed with HeartCrypt during ransomware intrusions
(RansomHub, INC, others). Sample-specific driver names (e.g., mraml.sys,
noedt.sys) are hard-coded in the payload.
Categories: vulnerable driver, verified
View authoritative reference β
WINIODrv.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, verified
View authoritative reference β
Kinkajou.sys
Kinkajou.sys is a vulnerable kernel driver from the KeServiceDescriptorTable/vulnerable-drivers repository. The driver exposes dangerous kernel primitives to usermode.
Categories: vulnerable driver, verified
View authoritative reference β
HP_SWTOOLS_DRIVER.sys
HP_SWTOOLS_DRIVER exposes privileged CPU and memory operations through the \\.\HP_WKS_SWTOOLS_DRIVER device. Static analysis confirms IOCTLs for MSR read and write, performance-counter access, physical/MMIO mapping and read/write, PCI configuration access, port I/O, and a CPU-halt path. A standard user can reach the device after an administrator installs the driver.
Categories: vulnerable driver, verified
View authoritative reference β
RTCore64.sys
The driver in Micro-Star MSI Afterburner 4.6.2.15658 (aka RTCore64.sys and RTCore32.sys) allows any authenticated user to read and write to arbitrary memory, I/O ports, and MSRs. This can be exploited for privilege escalation, code execution under high privileges, and information disclosure. These signed drivers can also be used to bypass the Microsoft driver-signing policy to deploy malicious code.
Categories: vulnerable driver, verified
View authoritative reference β
dkrTK.sys
The User Agent tjr.exe, which is protected via a virtual machine, drops the kernel driver to the user temporary directory C:\%User%\AppData\Local\Temp\Ktgn.sys. It then installs the dropped driver with the name ktgn and the start value = System (to start when the system restarts). From our analysis of what occurs when a user interfaces with this driver, we observed that it only uses one of the exposed Device Input and Output Control (IOCTL) code β Kill Process, which is used to kill security agent processes installed on the system.
Categories: malicious, verified
View authoritative reference β
POORTRY2.sys
Driver categorized as POORTRY by Mandiant.
Categories: malicious, verified
View authoritative reference β
PGPwded.sys
PGPwded.sys and eedDiskEncryptionDriver.sys are Symantec drive-encryption filters affected by CVE-2019-9702 and CVE-2019-9703. Symantec Endpoint Encryption releases before 11.3.0 and all Symantec Encryption Desktop releases are affected. The tracked filters expose raw-sector read and write controls. In the 11.1.1 eedDiskEncryptionDriver build, any-access IOCTLs 0x8002206C and 0x80022070 select a tracked volume and read or write sectors; its protected-range logic still permits writes beginning in sectors 0 through 2, leaving boot-sector modification possible.
Categories: vulnerable driver, verified
View authoritative reference β
dbk64.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, verified
View authoritative reference β
Khwmon.sys
Khwmon.sys is a vulnerable kernel driver from the KeServiceDescriptorTable/vulnerable-drivers repository. The driver exposes dangerous kernel primitives to usermode.
Categories: vulnerable driver, verified
View authoritative reference β
BdApiUtil.sys
BdApiUtil.sys is a kernel driver from Baidu Antivirus that exposes dangerous primitives to usermode with no authentication. The driver provides process termination by PID via PsLookupProcessByProcessId and ZwTerminateProcess (IOCTL 0x800024B4), process suspension via dynamically-resolved NtSuspendProcess (IOCTL 0x800024B8), full kernel registry CRUD including ZwOpenKey (0x80002190), ZwCreateKey (0x80002194), ZwSetValueKey (0x80002198), ZwDeleteKey (0x8000219C), and ZwDeleteValueKey (0x800021A0), and kernel-mode file creation via ObInsertObject/ZwCreateFile (0x80002324). The process termination primitive is exploited by the GoodBaiii EDR killer tool. Registry callback monitoring via CmRegisterCallback and process creation monitoring via PsSetCreateProcessNotifyRoutine are also present.
Categories: vulnerable driver, verified
View authoritative reference β
GEDevDrv.SYS
The Carbon Black Threat Analysis Unit (TAU) discovered 34 unique vulnerable drivers (237 file hashes) accepting firmware access. Six allow kernel memory access. All give full control of the devices to non-admin users. By exploiting the vulnerable drivers, an attacker without the system privilege may erase/alter firmware, and/or elevate privileges. As of the time of writing in October 2023, the filenames of the vulnerable drivers have not been made public until now.
Categories: vulnerable driver, verified
View authoritative reference β
elbycdio.sys
elbycdio.sys is a vulnerable driver. CVE-2009-0824.
Categories: vulnerable driver, verified
View authoritative reference β
FH-EtherCAT_DIO.sys
The Carbon Black Threat Analysis Unit (TAU) discovered 34 unique vulnerable drivers (237 file hashes) accepting firmware access. Six allow kernel memory access. All give full control of the devices to non-admin users. By exploiting the vulnerable drivers, an attacker without the system privilege may erase/alter firmware, and/or elevate privileges. As of the time of writing in October 2023, the filenames of the vulnerable drivers have not been made public until now.
Categories: vulnerable driver, verified
View authoritative reference β
echo_driver.sys
Bad access controls in Inspect Element Ltd.'s echo_driver.sys allows attacker to gain arbitrary memory read and write, which allows for easy Privilege Escalation via Token Theft.
Categories: vulnerable driver, verified
View authoritative reference β
asas.sys
Confirmed vulnerable driver from Microsoft Block List
Categories: vulnerable driver, verified
View authoritative reference β
piddrv64.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, verified
View authoritative reference β
nstrwsk.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, unverified
View authoritative reference β
nvoclock.sys
The Carbon Black Threat Analysis Unit (TAU) discovered 34 unique vulnerable drivers (237 file hashes) accepting firmware access. Six allow kernel memory access. All give full control of the devices to non-admin users. By exploiting the vulnerable drivers, an attacker without the system privilege may erase/alter firmware, and/or elevate privileges. As of the time of writing in October 2023, the filenames of the vulnerable drivers have not been made public until now.
Categories: vulnerable driver, verified
View authoritative reference β
asmmap64.sys
ASUS asmmap64 is a memory-mapping driver that exposes physical-memory mapping to user mode. A privileged caller can abuse the interface to read or modify kernel and physical memory.
Categories: vulnerable driver, verified
View authoritative reference β
NetworkLocker_x64.sys
NetworkLocker_x64.sys is a vulnerable kernel driver from the KeServiceDescriptorTable/vulnerable-drivers repository. The driver exposes dangerous kernel primitives to usermode.
Categories: vulnerable driver, verified
View authoritative reference β
ktgn.sys
BlackCat Ransomware Deploys New Signed Kernel Driver. BlackCat ransomware incident that occurred in February 2023.
Categories: malicious, unverified
View authoritative reference β
tboflhelper.sys
Northwave Cyber Security contributed this driver based on in-house research. The driver has a CVSSv3 score of 8.8, indicating a privelege escalation impact. This vulnerability could potentially be exploited for privilege escalation or other malicious activities.
Categories: vulnerable driver, verified
View authoritative reference β
IoAccess.sys
The Carbon Black Threat Analysis Unit (TAU) discovered 34 unique vulnerable drivers (237 file hashes) accepting firmware access. Six allow kernel memory access. All give full control of the devices to non-admin users. By exploiting the vulnerable drivers, an attacker without the system privilege may erase/alter firmware, and/or elevate privileges. As of the time of writing in October 2023, the filenames of the vulnerable drivers have not been made public until now.
Categories: vulnerable driver, verified
View authoritative reference β
MsIo32.sys
The MsIo64.sys and MsIo32.sys drivers in Patriot Viper RGB before 1.1 allow local users (including low integrity processes) to read and write to arbitrary memory locations, and consequently gain NT AUTHORITY\SYSTEM privileges, by mapping \Device\PhysicalMemory into the calling process via ZwOpenSection and ZwMapViewOfSection.
Categories: vulnerable driver, verified
View authoritative reference β
BSMEMx64.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, verified
View authoritative reference β
Sense5Ext.sys
Driver categorized as POORTRY by Mandiant.
Categories: malicious, verified
View authoritative reference β
7.sys
Driver categorized as POORTRY by Mandiant.
Categories: malicious, verified
View authoritative reference β
driver7-x64.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, verified
View authoritative reference β
skill.sys
Confirmed vulnerable driver from Microsoft Block List
Categories: vulnerable driver, verified
View authoritative reference β
windbg.sys
Kernel driver seen in a recent CopperStealer campaign.
Categories: malicious, verified
View authoritative reference β
ATSZIO.sys
ASUS ATSZIO64.sys version 0.2.1.7 is affected by CVE-2024-33222, which permits local privilege escalation and arbitrary code execution through crafted IOCTL requests. The tracked x64 build exposes MSR read and write through IOCTLs 0x88070F88 and 0x88070F8C, maps selected ranges of \Device\PhysicalMemory, and returns physical addresses for contiguous allocations. These unrestricted hardware primitives can be used to modify kernel state.
Categories: vulnerable driver, verified
View authoritative reference β
ALSysIO64.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, verified
View authoritative reference β
driver_668c5bea.sys
Sophos, from time to time, has observed a threat actor deploy variants of Poortry on different machines within a single estate during an attack. These variants contain the same payload, but signed with a different certificate than the driver first seen used during the attack.
Categories: malicious, verified
View authoritative reference β
VProEventMonitor.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, verified
View authoritative reference β
SBIOSIO64.sys
The Carbon Black Threat Analysis Unit (TAU) discovered 34 unique vulnerable drivers (237 file hashes) accepting firmware access. Six allow kernel memory access. All give full control of the devices to non-admin users. By exploiting the vulnerable drivers, an attacker without the system privilege may erase/alter firmware, and/or elevate privileges. As of the time of writing in October 2023, the filenames of the vulnerable drivers have not been made public until now.
Categories: vulnerable driver, verified
View authoritative reference β
LcTkA.sys
SentinelOne has observed prominent threat actors abusing legitimately signed Microsoft drivers in active intrusions into telecommunication, BPO, MSSP, and financial services businesses.
Investigations into these intrusions led to the discovery of POORTRY and STONESTOP malware, part of a small toolkit designed to terminate AV and EDR processes.
We first reported our discovery to Microsoftβs Security Response Center (MSRC) in October 2022 and received an official case number (75361). Today, MSRC released an associated advisory under ADV220005.
This research is being released alongside Mandiant, a SentinelOne technology and incident response partner.
Categories: malicious, verified
View authoritative reference β
IMFForceDelete
IObit Malware Fighter IMFForceDelete.sys is a vulnerable force-delete filter driver. ESET documents GentleKiller's Cleaner variant dropping this driver without the trailing .sys extension, and CVE-2019-6494 describes IOCTL 0x8016E000 allowing low-privileged users to delete files regardless of access controls.
Categories: vulnerable driver, verified
View authoritative reference β
KObjExp.sys
KObjExp.sys is Pavel Yosifovich's Kernel Object Explorer driver and is listed as a KDU-compatible provider. The staged samples include the KDU provider hash and a separate JobExplorer build of the same driver family.
Categories: vulnerable driver, verified
View authoritative reference β
TPwSav.sys
A driver associated with Toshiba laptops power saving functionality allows arbitary one byte reading and writing mapped physical addresses. Blackpoint Cyber's SOC observed this driver being used as part of a custom EDRSandblast malware to blind EDR prior to Qilin ransomware deployment.
Categories: vulnerable driver, verified
View authoritative reference β
DsArk64.sys
DsArk64.sys is a WHQL Microsoft-signed anti-rootkit kernel driver from Qihoo 360 Total Security. It exposes kernel-level process termination via ZwTerminateProcess from Ring 0 (kills PPL-protected processes), arbitrary kernel memory read (512 bytes), and arbitrary kernel memory write (32 bytes). The driver gates device access behind a custom Authenticode signing check that validates the calling process PE signature against Qihoo root certificates. This check is fully bypassed via process hollowing into any Qihoo-signed executable (freely downloadable from 360.cn). The process kill IOCTL (0x80863008) requires no encryption or additional auth beyond the device open -- just a raw 4-byte PID. The kernel R/W IOCTLs use AES-128-CBC with a static key embedded in the binary. Initialization requires setting registry key HKLM\SYSTEM\CCS\Services\360FsFlt\daboot to 1.
Categories: vulnerable driver, verified
View authoritative reference β
6c8a.sys
6c8a.sys is a vulnerable kernel driver from the KeServiceDescriptorTable/vulnerable-drivers repository. The driver exposes dangerous kernel primitives to usermode.
Categories: vulnerable driver, verified
View authoritative reference β
AsmIo64.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, verified
View authoritative reference β
rtcoremini64.sys
Confirmed vulnerable driver from Microsoft Block List
Categories: vulnerable driver, verified
View authoritative reference β
MemLoaderCustomize.sys
Nextron Systems identifies these samples as MemLoaderCustomize kernel PE-loader variants. Capabilities reported across the pair include kernel hooking, module hiding, and deletion; module hiding is specifically attributed to the c6825f94 sample. Static analysis confirms matching loader implementations that allocate image memory, copy PE sections, apply relocations, resolve kernel imports, and prepare mapped-image execution, together with file-deletion helpers. Both contain a MemLoaderCustomize.pdb build path. Module hiding and successful runtime self-deletion remain source-reported rather than dynamically tested.
Categories: malicious, verified
View authoritative reference β
wamsdk.sys
Vulnerable WatchDog Antimalware driver used by Silver Fox APT group to load unsigned drivers and execute malicious code in kernel mode
Categories: vulnerable driver, verified
View authoritative reference β
amp.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, verified
View authoritative reference β
filnk.sys
Twister Antivirus, fildds.sys, DoS2
CVE-2023-1444
From IoControlCode 0x8011206B, a normal user can cause DoS due to writing into
null address.
Categories: vulnerable driver, verified
View authoritative reference β
BS_Def64.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, verified
View authoritative reference β
BSMIx64.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, verified
View authoritative reference β
windows-xp-64.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, unverified
View authoritative reference β
ASIO32.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, unverified
View authoritative reference β
rtif.sys
The Carbon Black Threat Analysis Unit (TAU) discovered 34 unique vulnerable drivers (237 file hashes) accepting firmware access. Six allow kernel memory access. All give full control of the devices to non-admin users. By exploiting the vulnerable drivers, an attacker without the system privilege may erase/alter firmware, and/or elevate privileges. As of the time of writing in October 2023, the filenames of the vulnerable drivers have not been made public until now.
Categories: vulnerable driver, verified
View authoritative reference β
shield.sys
Horizon DataSys Shield drivers expose IOCTL functionality reported to provide arbitrary kernel read/write primitives.
Categories: vulnerable driver, verified
View authoritative reference β
SysDrv3S.sys
Vulnerable driver found in https://github.com/hfiref0x/KDU.
Categories: vulnerable driver, verified
View authoritative reference β
dtr_ec.sys
dtr_ec.sys is a Dell kernel driver that ships as part of the Dell Feature Enhancement Pack (DFEP) on Dell laptops and desktops. The driver provides unrestricted read/write access to Embedded Controller (EC) registers across 5 ACPI address spaces from usermode with no validation on the register addresses or values. The Embedded Controller manages critical hardware functions including thermal management, battery charging, fan control, power states, and keyboard input. Unrestricted EC register access allows manipulation of thermal thresholds to cause hardware damage or forced shutdowns, modification of fan speed controls, interference with battery charging logic, and alteration of power management behavior. Dell PSIRT has confirmed the vulnerability and triaged it as P2 severity on Bugcrowd.
Categories: vulnerable driver, unverified
View authoritative reference β
b.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, unverified
View authoritative reference β
CcProtect.sys
CnCrypt CcProtect.sys is a signed kernel driver used by BlackSnufkin BYOVD research as a process-killer provider. The public PoC documents this hash as a vulnerable CcProtect driver and notes that HVCI must be disabled to avoid instability.
Categories: vulnerable driver, verified
View authoritative reference β
elrawdsk.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, verified
View authoritative reference β
GLCKIO2.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, verified
View authoritative reference β
wantd.sys
Driver used in the Daxin malware campaign.
Categories: malicious, verified
View authoritative reference β
gvcidrv64.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, verified
View authoritative reference β
GVCIDrv64.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, verified
View authoritative reference β
NTIOLib.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, verified
View authoritative reference β
ProtectS.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, verified
View authoritative reference β
throttlestop.sys
ThrottleStop is developed by TechPowerUp and is designed to monitor for and correct CPU throttling issues. However, Kaspersky researchers from the Global Emergency Response Team (GERT) found out that it is being abused by attackers to terminate defense mechanisms.
Categories: vulnerable driver, verified
View authoritative reference β
probmon.sys
A vulnerable kernel driver that can be used to terminate arbitrary processes
Categories: vulnerable driver, verified
View authoritative reference β
dddriver64Dcsa.sys
dddriver64Dcsa.sys is a vulnerable kernel driver from the KeServiceDescriptorTable/vulnerable-drivers repository. The driver exposes dangerous kernel primitives to usermode.
Categories: vulnerable driver, verified
View authoritative reference β
wsdkd.sys
A vulnerability was found in Watchdog Anti-Virus 1.4.214.0. It has been rated as critical. Affected by this issue is the function 0x80002008 in the library wsdk-driver.sys of the component IoControlCode Handler. The manipulation leads to improper access controls. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used. VDB-223298 is the identifier assigned to this vulnerability.
Categories: vulnerable driver, verified
View authoritative reference β
driver_77225a99.sys
Sophos, from time to time, has observed a threat actor deploy variants of Poortry on different machines within a single estate during an attack. These variants contain the same payload, but signed with a different certificate than the driver first seen used during the attack.
Categories: malicious, verified
View authoritative reference β
ATSZIO.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, verified
View authoritative reference β
6771b13a53b9c7449d4891e427735ea2.sys
Cisco Talos has identified multiple versions of an undocumented malicious driver named βRedDriver,β a driver-based browser hijacker that uses the Windows Filtering Platform (WFP) to intercept browser traffic. RedDriver has been active since at least 2021. RedDriver utilizes HookSignTool to forge its signature timestamp to bypass Windows driver-signing policies. Code from multiple open-source tools has been used in the development of RedDriver's infection chain, including HP-Socket and a custom implementation of ReflectiveLoader. The authors of RedDriver appear to be skilled in driver development and have deep knowledge of the Windows operating system. This threat appears to target native Chinese speakers, as it searches for Chinese language browsers to hijack. Additionally, the authors are likely Chinese speakers themselves.
Categories: malicious, verified
View authoritative reference β
ndislan.sys
Driver used in the Daxin malware campaign.
Categories: malicious, verified
View authoritative reference β
windows7-32.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, unverified
View authoritative reference β
_xyzxbqvb.rdu_GFAC_Sys_x64.sys
_xyzxbqvb.rdu_GFAC_Sys_x64.sys is a vulnerable kernel driver from the KeServiceDescriptorTable/vulnerable-drivers repository. The driver exposes dangerous kernel primitives to usermode.
Categories: vulnerable driver, verified
View authoritative reference β
LHA.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, verified
View authoritative reference β
CorMem.sys
Teledyne Digital Imaging CorMem.sys (Sapera Memory Manager) exposes physical memory read/write, contiguous memory allocation, and I/O port access to user-mode processes via CorMem.dll wrapper functions. The driver provides 36 exported functions including CorMemGetPhysMemory, CorMemMapPhysMemory, CorMemAllocPhysMemory, CorMemReadIo, and CorMemWriteIo. Actively abused for BYOVD with 0/71 VT detection. Execution parents include Cobalt Strike/IcedID malware and game cheat kernel loaders.
Categories: vulnerable driver, verified
View authoritative reference β
PDFWKRNL.sys
AMD USB-C Power Delivery Firmware Update Kernel Library driver with arbitrary physical memory read/write capabilities. Identified in ESET EDR killers research (March 2026) as actively abused by threat actors to disable EDR products.
Categories: vulnerable driver, verified
View authoritative reference β
bsitf.sys
bsitf.sys and AsusBSItf.sys are ASUS BIOS Flash Driver naming variants distributed with the ASUS WinFlash utility. The 3.2.12.0 AsusBSItf.sys build exposes physical-memory reads through MmMapIoSpace (IOCTL 0x222804), contiguous kernel-memory allocation mapped to user mode through an MDL (IOCTL 0x222808), arbitrary I/O-port writes and reads (IOCTLs 0x222810 and 0x222818), and PCI configuration-space reads with BAR mapping (IOCTL 0x222814). Public research identifies this low-privilege interface as CVE-2024-33221 and demonstrates its use for privilege escalation, kernel code execution, or information disclosure. Earlier bsitf.sys builds tracked in this record additionally expose BIOS flash writes through IOCTL 0x22281C.
Categories: vulnerable driver, verified
View authoritative reference β
physmem.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, verified
View authoritative reference β
Lallamon.sys
Lallamon.sys is a vulnerable kernel driver from the KeServiceDescriptorTable/vulnerable-drivers repository. The driver exposes dangerous kernel primitives to usermode.
Categories: vulnerable driver, verified
View authoritative reference β
gibepext.sys
gibepext.sys is a vulnerable kernel driver from the KeServiceDescriptorTable/vulnerable-drivers repository. The driver exposes dangerous kernel primitives to usermode.
Categories: vulnerable driver, verified
View authoritative reference β
XLHA.sys
XLHA.sys is a kernel driver from LG Electronics Inc. that exposes physical memory read/write via MmMapIoSpace and MSR read. Two other LG LHA.sys variants are already tracked in LOLDrivers. The driver is available in the KeServiceDescriptorTable/vulnerable-drivers repository.
Categories: vulnerable driver, verified
View authoritative reference β
KRegExp.sys
KRegExp.sys is Pavel Yosifovich's Kernel Registry Explorer driver and is listed as a KDU-compatible provider. KDU uses provider drivers to perform privileged kernel operations including kernel memory access and process-object manipulation.
Categories: vulnerable driver, verified
View authoritative reference β
ArgusMonitor.sys
ArgusMonitor.sys is the kernel driver for the Argus Monitor hardware temperature monitoring and fan control application by Argotronic UG (Germany). The driver exposes 47 IOCTLs providing arbitrary physical memory read/write via MmMapIoSpace (32 map slots, up to 128KB) with a single-shot read primitive that bypasses the address restriction (busNum=0xFF), unrestricted port I/O (any port 0x0000-0xFFFF), PCI configuration space read/write via HalGetBusDataByOffset and HalSetBusDataByOffset, MSR read/write with a whitelist that blocks IA32_LSTAR but allows IA32_MISC_ENABLE write (can disable NX/XD system-wide), and I2C/SMBus access via MMIO bit-banging. The driver uses IoCreateDevice with no DACL and IRP_MJ_CREATE returns STATUS_SUCCESS immediately with no caller validation. A handshake IOCTL accepts a user-chosen 0x200-byte XOR keypad (sending all zeros effectively disables the XOR layer). WHQL attestation signed with an active Microsoft certificate. KASLR bypass confirmed via physical memory PE header scan. Loads on any x64 Windows without ArgusMonitor software.
Categories: vulnerable driver, verified
View authoritative reference β
Driver_win10.sys
Kernel driver family observed dropped by Black Basta tooling and adjacent intrusions during 2025. The 55 KB sample is signed by Microsoft Windows Hardware Compatibility Publisher (WHQL attestation), allowing it to load on systems with HVCI enabled. Two additional 44 KB unsigned variants share the same imphash and identical/near-identical authentihashes, indicating the same driver body redistributed without the embedded signature blob. Imports include FltEnumerateFilters and FltUnregisterFilter (minifilter enumeration and unregistration), MmCopyVirtualMemory (cross-process kernel-assisted memory copy), ZwTerminateProcess and ZwOpenProcess (process termination), and KeStackAttachProcess (process attach) β primitives suitable for tamper protection or evasion of endpoint security minifilters.
Categories: vulnerable driver, verified
View authoritative reference β
smep_namco.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, verified
View authoritative reference β
WinIO32.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, unverified
View authoritative reference β
rksafe.sys
Nextron Systems identifies this rksafe sample as a rootkit with input interception, anti-debugging, minifilter callbacks, and process protection. Static analysis confirms cross-process memory read/write routines, minifilter registration with a communication port, process and thread object callbacks, and logic that clears KdDebuggerEnabled. Input interception and successful runtime protection effects were not independently tested.
Categories: malicious, verified
View authoritative reference β
kbdcap64.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, verified
View authoritative reference β
daxin_blank6.sys
Driver used in the Daxin malware campaign.
Categories: malicious, verified
View authoritative reference β
driver_1a74c2bd.sys
Sophos, from time to time, has observed a threat actor deploy variants of Poortry on different machines within a single estate during an attack. These variants contain the same payload, but signed with a different certificate than the driver first seen used during the attack.
Categories: malicious, verified
View authoritative reference β
sfdrvx32.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, verified
View authoritative reference β
dbutil_2_3.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, verified
View authoritative reference β
telephonuAfY.sys
Cisco Talos has identified multiple versions of an undocumented malicious driver named βRedDriver,β a driver-based browser hijacker that uses the Windows Filtering Platform (WFP) to intercept browser traffic. RedDriver has been active since at least 2021.
RedDriver utilizes HookSignTool to forge its signature timestamp to bypass Windows driver-signing policies.
Code from multiple open-source tools has been used in the development of RedDriver's infection chain, including HP-Socket and a custom implementation of ReflectiveLoader.
The authors of RedDriver appear to be skilled in driver development and have deep knowledge of the Windows operating system.
This threat appears to target native Chinese speakers, as it searches for Chinese language browsers to hijack. Additionally, the authors are likely Chinese speakers themselves.
Categories: malicious, verified
View authoritative reference β
fildds.sys
Twister Antivirus, fildds.sys, DoS2
CVE-2023-1444
From IoControlCode 0x8011206B, a normal user can cause DoS due to writing into null address.
Categories: vulnerable driver, verified
View authoritative reference β
pstrip64.sys
pstrip64.sys is the EnTech Taiwan PowerStrip x64 kernel-mode driver, signed by EnTech Taiwan. In PowerStrip version 3.90.736 and earlier, the driver's IOCTL dispatcher exposes code 0x80002008, which maps caller-supplied physical memory directly into the requesting user-mode process and returns the mapped virtual base address, giving a local user an arbitrary physical read/write primitive. Public exploitation of CVE-2026-29923 uses this to scan physical memory for the EPROCESS 'Proc' pool tag, copy the SYSTEM process token, and overwrite the caller's token to escalate to NT AUTHORITY\SYSTEM.
Categories: vulnerable driver, verified
View authoritative reference β
CupFixerx64.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, verified
View authoritative reference β
DirectIo.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, unverified
View authoritative reference β
BS_I2cIo.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, verified
View authoritative reference β
athpexnt.sys
AhnLab kernel driver exposing arbitrary physical memory read/write via IOCTL 0x81000000. Device accessible at \\.\ATHpEx. Signed by AhnLab Inc. with VeriSign certificate (first seen 2014). Zero detections (0/73) on VirusTotal but exploitable for privilege escalation by mapping attacker-controlled physical memory into kernel address space.
Categories: vulnerable driver, verified
View authoritative reference β
Realtime Driver.sys
Realtime Driver.sys is a vulnerable kernel driver from the KeServiceDescriptorTable/vulnerable-drivers repository. The driver exposes dangerous kernel primitives to usermode.
Categories: vulnerable driver, verified
View authoritative reference β
t7.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, unverified
View authoritative reference β
driver_d1ea9e16.sys
Sophos, from time to time, has observed a threat actor deploy variants of Poortry on different machines within a single estate during an attack. These variants contain the same payload, but signed with a different certificate than the driver first seen used during the attack.
Categories: malicious, verified
View authoritative reference β
ntbios_2.sys
Driver used in the Daxin malware campaign.
Categories: malicious, verified
View authoritative reference β
wfshbr64.sys
wfshbr64.sys and wfshbr32.sys specially crafted payload allows arbitrary user to perform bitwise operation with arbitrary EPROCESS offset and flags value to purposely elevate the game process to CodeGen Full protection by manipulating EPROCESS.Protection and EPROCESS.SignatureLevel flags (security hole as a feature).
The driver is signed by Microsoft hardware compatibility publisher that is submitted via Microsoft Hardware Program.
Categories: malicious, verified
View authoritative reference β
TcIo.sys
TcIo.sys and TcRouter.sys are WHQL Microsoft-signed kernel drivers from Beckhoff Automation GmbH (TwinCAT 3 Industrial Automation Runtime). TcIo.sys exposes arbitrary physical memory read/write via ZwOpenSection on Device\PhysicalMemory, arbitrary MMIO mapping via MmMapIoSpace, PCI configuration space read/write via HalGetBusDataByOffset and HalSetBusDataByOffset, and full PCI BAR probing and mapping. TcRouter.sys exposes arbitrary port I/O via direct ring-0 in/out instructions. Both drivers use plain IoCreateDevice with no DACL and have no caller validation on IRP_MJ_CREATE. All IOCTLs use METHOD_NEITHER with FILE_ANY_ACCESS. No hardware gate -- drivers load on any x64 Windows without Beckhoff hardware. CVE-2018-7502 was assigned for an untrusted pointer dereference in IOCTL 0x222206 affecting 19 drivers in the TwinCAT family (CISA advisory ICSA-18-081-02, Source Incite SRC-2018-0007). The physical memory and port I/O primitives described here go beyond the scope of CVE-2018-7502. 18 related drivers share the same codebase and certificate.
Categories: vulnerable driver, verified
View authoritative reference β
tdevflt.sys
This ABYSSWORKER-related malicious kernel driver presents as Palo Alto Networks tdevflt.sys / Cortex XDR PnP Device Filter Driver. Public DragonForce reporting lists the sample in a BYOVD tradecraft set alongside known vulnerable process-killer drivers.
Categories: malicious, verified
View authoritative reference β
1.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, unverified
View authoritative reference β
szkg64.sys
The StopZilla driver is a forgotten but still exploitable vulnerable driver that allows arbitrary kernel memory writes via unvalidated IOCTLs (0x80002063 and 0x8000206F). Attackers can leverage it to escalate privileges, disable LSASS PPL protection, and even modify PreviousMode in _KTHREAD to execute user-mode code as kernel-mode, effectively bypassing security checks. Despite its risks, it remains unblocked by Microsoftβs Driver Block List and many AV/EDR solutions. This driver highlights the persistent threat of forgotten vulnerable drivers still exploitable in modern Windows environments.
Categories: vulnerable driver, verified
View authoritative reference β
NQrmq.sys
Found via RichPEHeaderHash pivoting.
Categories: malicious, verified
View authoritative reference β
ktes.sys
BlackCat Ransomware Deploys New Signed Kernel Driver. BlackCat ransomware incident that occurred in February 2023.
Categories: malicious, unverified
View authoritative reference β
TRIXX.sys
TRIXX.sys is a shared utility kernel driver distributed by TechPowerUp LLC with Sapphire TRIXX and GPU-Z. The driver provides completely unrestricted hardware access from usermode through 16+ IOCTLs with zero validation on hardware parameters, including arbitrary port I/O read/write, arbitrary PCI configuration space read/write via HalGetBusDataByOffset/HalSetBusDataByOffset, MMIO BAR mapping via MmMapIoSpace, and MMIO read/write through mapped BARs. Physical memory read/write is achievable by remapping a PCI device BAR to a target physical address then mapping it via MmMapIoSpace. The driver creates its device dynamically based on the Windows service name and has no hardware dependency, loading on any x64 Windows system. TechPowerUp has a history of vulnerable kernel drivers including GPU-Z.sys (CVE-2019-7245, CVE-2025-5324) and ThrottleStop.sys (CVE-2025-7771) which expose the same MmMapIoSpace primitive. Fresh EV code signing certificate valid until April 2028 with zero AV detections.
Categories: vulnerable driver, verified
View authoritative reference β
HW.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, verified
View authoritative reference β
Chaos-Rootkit.sys
Chaos-Rootkit is a x64 ring0 rootkit with process hiding, privilege escalation, and capabilities for protecting and unprotecting processes, work on the latest Windows versions.
Categories: vulnerable driver, verified
View authoritative reference β
dbutil.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, unverified
View authoritative reference β
WCPU.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, verified
View authoritative reference β
LHA.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, verified
View authoritative reference β
BS_HWMIo64.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, verified
View authoritative reference β
SysInfoX64.sys
SysInfoX64.sys is a vulnerable kernel driver from the KeServiceDescriptorTable/vulnerable-drivers repository. The driver exposes dangerous kernel primitives to usermode.
Categories: vulnerable driver, verified
View authoritative reference β
vboxguest.sys
Confirmed vulnerable driver from Microsoft Block List
Categories: vulnerable driver, verified
View authoritative reference β
ecsiodriverx64.sys
The Carbon Black Threat Analysis Unit (TAU) discovered 34 unique vulnerable drivers (237 file hashes) accepting firmware access. Six allow kernel memory access. All give full control of the devices to non-admin users. By exploiting the vulnerable drivers, an attacker without the system privilege may erase/alter firmware, and/or elevate privileges. As of the time of writing in October 2023, the filenames of the vulnerable drivers have not been made public until now.
Categories: vulnerable driver, verified
View authoritative reference β
bwrsh.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, unverified
View authoritative reference β
UDDB2B6.sys
UDDB2B6.sys is a TechPowerUp kernel driver (GPU-Z variant) that exposes I/O port read/write, MSR read/write, MmMapIoSpace map/unmap/read/write, and PCI configuration space read/write. TechPowerUp has a history of vulnerable kernel drivers including GPU-Z.sys (CVE-2019-7245, CVE-2025-5324) and ThrottleStop.sys (CVE-2025-7771). The driver is available in the KeServiceDescriptorTable/vulnerable-drivers repository.
Categories: vulnerable driver, verified
View authoritative reference β
GameTerSafe.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, unverified
View authoritative reference β
isodrivep64.sys
ABYSSWORKER is a malicious driver used in MEDUSA ransomware attacks to disable EDR systems. The driver masquerades as a legitimate CrowdStrike Falcon driver and provides extensive capabilities to terminate processes, remove security callbacks, manipulate files, and disable security tools. It uses stolen certificates from Chinese companies and requires a specific password for activation. The driver was observed being deployed alongside HEARTCRYPT-packed loaders and provides attackers with kernel-level capabilities to blind EDR products by removing notification callbacks, detaching mini-filter devices, and replacing driver major functions.
Categories: vulnerable driver, verified
View authoritative reference β
nvflsh64.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, verified
View authoritative reference β
nscm.sys
nscm.sys is a vulnerable driver. CVE-2013-3956.
Categories: vulnerable driver, verified
View authoritative reference β
AsrSmartConnectDrv.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, verified
View authoritative reference β
VBoxUSBMon.sys
Confirmed vulnerable driver from Microsoft Block List
Categories: vulnerable driver, verified
View authoritative reference β
nscm.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, verified
View authoritative reference β
mhyprotnap.sys
Confirmed vulnerable driver from Microsoft Block List
Categories: vulnerable driver, verified
View authoritative reference β
MSqPq.sys
BlackCat Ransomware Deploys New Signed Kernel Driver. BlackCat ransomware incident that occurred in February 2023.
Categories: malicious, verified
View authoritative reference β
Dh_Kernel_10.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, verified
View authoritative reference β
pxitrig64.sys
Northwave Cyber Security contributed this driver based on in-house research. The driver has a CVSSv3 score of 5.5, indicating a local dos impact. This vulnerability could potentially be exploited for privilege escalation or other malicious activities.
Categories: vulnerable driver, verified
View authoritative reference β
1109.sys
1109.sys is a vulnerable kernel driver from the KeServiceDescriptorTable/vulnerable-drivers repository. The driver exposes dangerous kernel primitives to usermode.
Categories: vulnerable driver, verified
View authoritative reference β
nt3.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, unverified
View authoritative reference β
truesight.sys
This is a C# AV/EDR Killer using Rogue Anti-Malware Driver 3.3. This driver is not present in the loldrivers or Windows blocklist at the time of this writing. The only reason I'm making this public is because the company has already published a fix in version 3.4, and Microsoft will likely block this driver soon. This driver can be used in Windows 23H2 with HVCI enabled, loldrivers blocklist, or WDAC enabled. HVCI is designed to ensure the integrity of code executed in the kernel, but it cannot protect against all possible vulnerabilities or actions that can be performed through drivers or system interfaces.
Categories: vulnerable driver, verified
View authoritative reference β
Amd_RPMC_BiosToolCommonDriver.sys
Amd_RPMC_BiosToolCommonDriver.sys is a vulnerable kernel driver from the KeServiceDescriptorTable/vulnerable-drivers repository. The driver exposes dangerous kernel primitives to usermode.
Categories: vulnerable driver, verified
View authoritative reference β
Chaos-Rootkit.sys
Chaos-Rootkit is a x64 ring0 rootkit with process hiding, privilege escalation, and capabilities for protecting and unprotecting processes and ability to restrict access to files except for whitelisted process work seamlessly on the latest Windows versions.
Categories: vulnerable driver, verified
View authoritative reference β
TdkLib64.sys
The Carbon Black Threat Analysis Unit (TAU) discovered 34 unique vulnerable drivers (237 file hashes) accepting firmware access. Six allow kernel memory access. All give full control of the devices to non-admin users. By exploiting the vulnerable drivers, an attacker without the system privilege may erase/alter firmware, and/or elevate privileges. As of the time of writing in October 2023, the filenames of the vulnerable drivers have not been made public until now.
Categories: vulnerable driver, verified
View authoritative reference β
GGProtect64.sys
GGProtect64.sys is a Microsoft-signed anticheat kernel driver for GGη§ε· that exposes a \\.\GGProtect64 device. Public research documents a bypassable caller-registration flow through IOCTL 0x223C14 and a privileged process termination path through IOCTL 0x223C04, allowing a local process to terminate or suspend protected processes from kernel mode.
Categories: vulnerable driver, verified
View authoritative reference β
mJj0ge.sys
The criminals signed their AV-killer malware, closely related to one known as BURNTCIGAR, with a legitimate WHCP certificate
Categories: malicious, verified
View authoritative reference β
smep_capcom.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, verified
View authoritative reference β
c94f405c5929cfcccc8ad00b42c95083.sys
Cisco Talos has identified multiple versions of an undocumented malicious driver named βRedDriver,β a driver-based browser hijacker that uses the Windows Filtering Platform (WFP) to intercept browser traffic. RedDriver has been active since at least 2021. RedDriver utilizes HookSignTool to forge its signature timestamp to bypass Windows driver-signing policies. Code from multiple open-source tools has been used in the development of RedDriver's infection chain, including HP-Socket and a custom implementation of ReflectiveLoader. The authors of RedDriver appear to be skilled in driver development and have deep knowledge of the Windows operating system. This threat appears to target native Chinese speakers, as it searches for Chinese language browsers to hijack. Additionally, the authors are likely Chinese speakers themselves.
Categories: malicious, verified
View authoritative reference β
360netmon_wfp.sys
Qihoo 360netmon_wfp.sys is a signed kernel driver documented by ESET as the driver abused by the GentleKiller Network Blocker variant used in Gentlemen ransomware intrusions. The sample is associated with ESET detection Win64/VulnDriver.Qihoo360.A.
Categories: vulnerable driver, verified
View authoritative reference β
driver_0ffb4081.sys
Sophos, from time to time, has observed a threat actor deploy variants of Poortry on different machines within a single estate during an attack. These variants contain the same payload, but signed with a different certificate than the driver first seen used during the attack.
Categories: malicious, verified
View authoritative reference β
mhyprotect.sys
Confirmed vulnerable driver from Microsoft Block List
Categories: vulnerable driver, verified
View authoritative reference β
amigendrv64.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, verified
View authoritative reference β
mhyprotrpg.Sys
Confirmed vulnerable driver from Microsoft Block List
Categories: vulnerable driver, verified
View authoritative reference β
ViveRRAudio.sys
Northwave Cyber Security contributed this driver based on in-house research. The driver has a CVSSv3 score of 5.5, indicating a information disclosure / local dos impact. This vulnerability could potentially be exploited for privilege escalation or other malicious activities.
Categories: vulnerable driver, verified
View authoritative reference β
fiddrv.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, unverified
View authoritative reference β
Bs_Def.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, unverified
View authoritative reference β
PGRHostControl.sys
PGRHostControl.sys is a signed kernel driver distributed by FLIR Integrated Imaging Solutions, Inc. (formerly Point Grey Research). The driver exposes multiple privileged IOCTL handlers that can be accessed without sufficient authorization checks, allowing user-controlled requests to map arbitrary physical memory through \Device\PhysicalMemory and provides unrestricted I/O port read and write primitives via the x86 IN/OUT instructions. These capabilities can be abused to access physical RAM, interact directly with hardware registers, access MMIO regions, and potentially facilitate local privilege escalation or post-exploitation activity. Due to the absence of adequate access controls around highly privileged operations, the driver constitutes a Bring Your Own Vulnerable Driver (BYOVD) primitive.
Categories: vulnerable driver, verified
View authoritative reference β
GtcKmdfBs.sys
The Carbon Black Threat Analysis Unit (TAU) discovered 34 unique vulnerable drivers (237 file hashes) accepting firmware access. Six allow kernel memory access. All give full control of the devices to non-admin users. By exploiting the vulnerable drivers, an attacker without the system privilege may erase/alter firmware, and/or elevate privileges. As of the time of writing in October 2023, the filenames of the vulnerable drivers have not been made public until now.
Categories: vulnerable driver, verified
View authoritative reference β
viragt.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, verified
View authoritative reference β
gftkyj64.sys
SentinelOne has observed prominent threat actors abusing legitimately signed Microsoft drivers in active intrusions into telecommunication, BPO, MSSP, and financial services businesses.
Investigations into these intrusions led to the discovery of POORTRY and STONESTOP malware, part of a small toolkit designed to terminate AV and EDR processes.
We first reported our discovery to Microsoftβs Security Response Center (MSRC) in October 2022 and received an official case number (75361). Today, MSRC released an associated advisory under ADV220005.
This research is being released alongside Mandiant, a SentinelOne technology and incident response partner.
Categories: malicious, verified
View authoritative reference β
360hvm64.sys
360hvm64.sys is the kernel-mode hypervisor enforcement driver shipped with Qihoo 360 Total Security. IOCTL 0x22240c on \\.\360Hvm issues a per-CPU DPC broadcast that executes VMXOFF/VMSKINIT on every logical processor, disabling VT-x/AMD-V hypervisor protection across all CPUs; the auth gate (sub_121f4) delegates to \Device\360SelfProtection and fails open when that companion device is absent (BYOVD scenario).
Categories: vulnerable driver, verified
View authoritative reference β
amsdk.sys
Vulnerable WatchDog Antimalware driver used by Silver Fox APT group to load unsigned drivers and execute malicious code in kernel mode
Categories: vulnerable driver, verified
View authoritative reference β
devMemDrv.sys
devMemDrv.sys is a vulnerable kernel driver from the KeServiceDescriptorTable/vulnerable-drivers repository. The driver exposes dangerous kernel primitives to usermode.
Categories: vulnerable driver, verified
View authoritative reference β
NSecKrnl.sys
Driver used by ValleyRAT malware to terminate security processes via IOCTL 0x2248E0
Categories: vulnerable driver, verified
View authoritative reference β
BS_RCIO.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, verified
View authoritative reference β
hax.sys
Intel Hardware Accelerated Execution Manager versions before 7.7.1 are affected by CVE-2022-21812. The tracked 6.1.0 through 7.7.0 IntelHaxm.sys builds all precede the fixed release. Improper access control on the \Device\GHAX interface allows an authenticated local user to cross the user-to-kernel security boundary and elevate privileges.
Categories: vulnerable driver, verified
View authoritative reference β
2.sys
Driver categorized as POORTRY by Mandiant.
Categories: malicious, verified
View authoritative reference β
AsrDrv103.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, verified
View authoritative reference β
SONiXDDRx64.sys
SONiXDDRx64.sys is a vulnerable kernel driver from the KeServiceDescriptorTable/vulnerable-drivers repository. The driver exposes dangerous kernel primitives to usermode.
Categories: vulnerable driver, verified
View authoritative reference β
rwdrv.sys
This utility access almost all the computer hardware, including PCI (PCI Express), PCI Index/Data, Memory, Memory Index/Data, I/O Space, I/O Index/Data, Super I/O, Clock Generator, DIMM SPD, SMBus Device, CPU MSR Registers, ATA/ATAPI Identify Data, Disk Read Write, ACPI Tables Dump (include AML decode), Embedded Controller, USB Information, SMBIOS Structures, PCI Option ROMs, MP Configuration Table, E820, EDID and Remote Access. And also a Command Window is provided to access hardware manually.
Categories: vulnerable driver, verified
View authoritative reference β
KfeCo11X64.sys
Killer exposes COM interfaces that allow non-privileged users 1) to block network for any process 2) to manage any service in the OS. Killer is preinstalled to laptops equipped with Intel Killer NICs (e.g. Dell). Since Intel patched the vulnerability quietly, it's not clear which version is safe. Also, it is unclear which OEMs are affected. Dell is definitely in the list, but it is likely that other vendors with Killer NICs on board, such as Acer and MSI, are affected too. Some users think that Killer suite is required for the NIC to work properly, so they install it even after a fresh Windows install. This version is confirmed vulnerable based on the script usage from zwclose.
Categories: vulnerable driver, verified
View authoritative reference β
driver7-x86-withoutdbg.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, verified
View authoritative reference β
TGSafe.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, unverified
View authoritative reference β
VBoxUSB.Sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, verified
View authoritative reference β
driver_090d409f.sys
Sophos, from time to time, has observed a threat actor deploy variants of Poortry on different machines within a single estate during an attack. These variants contain the same payload, but signed with a different certificate than the driver first seen used during the attack.
Categories: malicious, verified
View authoritative reference β
FPCIE2COM.sys
FINTEK FPCIE2COM exposes FILE_ANY_ACCESS IOCTLs through \DosDevices\FPCIE2COM that map caller-selected physical addresses for byte reads and writes. It also permits raw PCI configuration access through I/O ports 0xCF8 and 0xCFC, creating privileged hardware-control primitives suitable for kernel or firmware tampering.
Categories: vulnerable driver, verified
View authoritative reference β
netflt.sys
Confirmed vulnerable driver from Microsoft Block List
Categories: vulnerable driver, verified
View authoritative reference β
phymem64.sys
Supermicro phymem drivers expose direct physical-memory operations to user mode. In the tracked 2.3.0.0 build, IOCTL 0x80002000 accepts a physical address and length, maps the range with MmMapIoSpace, builds an MDL, and maps the pages to user mode with MmMapLockedPagesSpecifyCache; 0x80002004 releases the mapping. Adjacent paths provide direct physical-memory reads and port I/O. An administrator with device access can use these primitives to inspect or modify kernel state.
Categories: vulnerable driver, verified
View authoritative reference β
netfilterdrv.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, verified
View authoritative reference β
KslD.sys
KslD.sys is a Microsoft-signed Windows Defender support driver that can be abused for kernel memory access after its SharedState process-name check is redirected to an attacker-controlled process. Public research documents IOCTL 0x222044 as exposing physical and virtual memory read primitives that can support KASLR bypass, token discovery, and LSASS/PPL bypass workflows.
Categories: vulnerable driver, verified
View authoritative reference β
FDMCJHJYXZITI.sys
FDMCJHJYXZITI.sys is a vulnerable kernel driver from the KeServiceDescriptorTable/vulnerable-drivers repository. The driver exposes dangerous kernel primitives to usermode.
Categories: vulnerable driver, verified
View authoritative reference β
magdrvamd64.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, verified
View authoritative reference β
whql.sys
whql.sys is a vulnerable kernel driver from the KeServiceDescriptorTable/vulnerable-drivers repository. The driver exposes dangerous kernel primitives to usermode.
Categories: vulnerable driver, verified
View authoritative reference β
AsrDrv102.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, verified
View authoritative reference β
wantd_5.sys
Driver used in the Daxin malware campaign.
Categories: malicious, verified
View authoritative reference β
NTIOLib_X64.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, verified
View authoritative reference β
wantd_2.sys
Driver used in the Daxin malware campaign.
Categories: malicious, verified
View authoritative reference β
d3.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, unverified
View authoritative reference β
SMARTEIO64.SYS
The Carbon Black Threat Analysis Unit (TAU) discovered 34 unique vulnerable drivers (237 file hashes) accepting firmware access. Six allow kernel memory access. All give full control of the devices to non-admin users. By exploiting the vulnerable drivers, an attacker without the system privilege may erase/alter firmware, and/or elevate privileges. As of the time of writing in October 2023, the filenames of the vulnerable drivers have not been made public until now.
Categories: vulnerable driver, verified
View authoritative reference β
viragt64.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, verified
View authoritative reference β
gmer64.sys
Driver used by the GMER application. Which is an application that detects and removes rootkits
Categories: malicious, verified
View authoritative reference β
NetFlt.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, unverified
View authoritative reference β
dpmemio.sys
ET&T Technology Co., Ltd. dpmemio.sys (ClevoECView) is a 12KB driver with only 9 imports that provides completely unrestricted arbitrary physical memory read/write and I/O port access with no authentication, no ACL, no address validation, and no size validation. MmUnmapIoSpace is not even imported, meaning every MmMapIoSpace call permanently leaks a system PTE mapping. An additional bug exists where MOVSXD sign-extension on a 32-bit UserBufferPtr provides a write-to-kernel-VA primitive. IOCTLs exposed via \\.\dpMemIO include 0xC80A2420 (arbitrary physical memory READ via MmMapIoSpace), 0xC80A2424 (arbitrary physical memory WRITE via MmMapIoSpace), 0xC80A2410/0xC80A2414 (I/O port read/write byte), 0xC80A2418/0xC80A241C (I/O port read/write variable size), and 0xC80A2428 (version/ping). VeriSign signed with a revoked certificate.
Categories: vulnerable driver, verified
View authoritative reference β
1fc7aeeff3ab19004d2e53eae8160ab1.sys
Cisco Talos has identified multiple versions of an undocumented malicious driver named βRedDriver,β a driver-based browser hijacker that uses the Windows Filtering Platform (WFP) to intercept browser traffic. RedDriver has been active since at least 2021. RedDriver utilizes HookSignTool to forge its signature timestamp to bypass Windows driver-signing policies. Code from multiple open-source tools has been used in the development of RedDriver's infection chain, including HP-Socket and a custom implementation of ReflectiveLoader. The authors of RedDriver appear to be skilled in driver development and have deep knowledge of the Windows operating system. This threat appears to target native Chinese speakers, as it searches for Chinese language browsers to hijack. Additionally, the authors are likely Chinese speakers themselves.
Categories: malicious, verified
View authoritative reference β
SIVX64.sys
Ray Hinchliffe SIV (System Information Viewer) SIVX64.sys v5.85 dynamically resolves MmMapIoSpace and MmMapIoSpaceEx via MmGetSystemRoutineAddress at runtime (neither appears in the IAT), evading static import-based scanning. The driver exposes multiple privileged IOCTL primitives via \\.\SIVDRIVER including arbitrary physical memory mapped read/write (Cmd 0x14, critical), physical memory read via scatter-gather (Cmd 0x10) and bulk MDL (Cmd 0x13), MSR read/write on a whitelisted subset (Cmd 0x08/0x0C), unrestricted I/O port read/scan (Cmd 0x44/0x50), and unrestricted PCI configuration space read (Cmd 0x48). WHQL signed by Microsoft Windows Hardware Compatibility Publisher; loads despite HVCI.
Categories: vulnerable driver, verified
View authoritative reference β
VBoxUSB.Sys
Confirmed vulnerable driver from Microsoft Block List
Categories: vulnerable driver, verified
View authoritative reference β
dcr.sys
DriveCrypt Dcr.sys vulnerability exploit for bypassing x64 DSE
Categories: vulnerable driver, verified
View authoritative reference β
changsha
Malicious rootkit masquerading as legitimate CrowdStrike Falcon Sensor driver (CSAgent.sys). Signed with stolen/expired Chinese certificate from 2015. Detected by 61.6% of AV engines as Rootkit.Win64.Agent and Trojan:Win64/AVTamper. Used to establish kernel-level persistence while evading detection by impersonating trusted security software.
Categories: malicious, verified
View authoritative reference β
driver_c3d48ddd.sys
Sophos, from time to time, has observed a threat actor deploy variants of Poortry on different machines within a single estate during an attack. These variants contain the same payload, but signed with a different certificate than the driver first seen used during the attack.
Categories: malicious, verified
View authoritative reference β
RtsUer.sys
The Realtek SD card reader driver, RtsUer.sys, versions below or equal to 10.0.22000.31273 contain multiple vulnerabilities that pose significant security risks. These flaws allow non-privileged users to write to kernel memory and access the DMA controller from unprivileged accounts, potentially enabling privilege escalation and system compromise. The most severe issues include the ability to write to kernel memory and access the DMA controller, which could lead to unauthorized system modifications. These vulnerabilities affect various Realtek SD card reader models used by major OEM laptop manufacturers. Due to the widespread use of this driver, the impact is considerable, potentially affecting a large number of systems across different brands. Users with laptops equipped with Realtek SD card readers should ensure their drivers are updated to a version higher than 10.0.22000.31273 to mitigate these security risks.
Categories: vulnerable driver, verified
View authoritative reference β
rtport.sys
The Carbon Black Threat Analysis Unit (TAU) discovered 34 unique vulnerable drivers (237 file hashes) accepting firmware access. Six allow kernel memory access. All give full control of the devices to non-admin users. By exploiting the vulnerable drivers, an attacker without the system privilege may erase/alter firmware, and/or elevate privileges. As of the time of writing in October 2023, the filenames of the vulnerable drivers have not been made public until now.
Categories: vulnerable driver, verified
View authoritative reference β
hp64vision.sys
hp64vision.sys is a vulnerable kernel driver from the KeServiceDescriptorTable/vulnerable-drivers repository. The driver exposes dangerous kernel primitives to usermode.
Categories: vulnerable driver, verified
View authoritative reference β
driver_206006a1.sys
Sophos, from time to time, has observed a threat actor deploy variants of Poortry on different machines within a single estate during an attack. These variants contain the same payload, but signed with a different certificate than the driver first seen used during the attack.
Categories: malicious, verified
View authoritative reference β
LenovoDiagnosticsDriver.sys
Lenovo Diagnostics versions before 4.45 are covered by CVE-2022-3699. The vulnerable driver behavior tracked here is limited to confirmed 1.0.2.0 through 1.0.4.0 LenovoDiagnosticsDriver.sys builds. Their low-user device ACL exposes FILE_ANY_ACCESS IOCTLs 0x222010 and 0x222014, which map caller-selected physical addresses and provide unrestricted physical-memory read and write primitives. Later 3.1.0.0 code removed the write path, denied Builtin Users, and limited reads to allowlisted PCI registers, so that build is not tracked here.
Categories: vulnerable driver, verified
View authoritative reference β
Tmel.sys
Confirmed vulnerable driver from Microsoft Block List
Categories: vulnerable driver, verified
View authoritative reference β
NetProxyDriver.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, unverified
View authoritative reference β
Driver7.sys
Confirmed vulnerable driver from Microsoft Block List
Categories: vulnerable driver, verified
View authoritative reference β
AccelLid.sys
AccelLid.sys is an Elitegroup Computer Systems lid accelerometer kernel driver. Northwave Cyber Security reported a local denial-of-service vulnerability with a CVSSv3 score of 5.5. The driver exposes IOCTL paths for accelerometer commands, keyboard control, event registration, and ACPI method execution. Microsoft's vulnerable driver blocklist denies AccelLid.sys across all file versions for matching Elitegroup publisher and signing roots.
Categories: vulnerable driver, verified
View authoritative reference β
ProcObsrvesx.sys
Northwave Cyber Security contributed this driver based on in-house research. The driver has a CVSSv3 score of 8.8, indicating a privilege escalation impact. This vulnerability could potentially be exploited for privilege escalation or other malicious activities.
Categories: vulnerable driver, verified
View authoritative reference β
WYProxy64.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, unverified
View authoritative reference β
WibuKey64.sys
WibuKey for Windows releases before 6.70 are affected by CVE-2024-45181 and CVE-2024-45182. Version 6.70 is separately affected by the boundary-validation flaw documented in WIBU-100057 and fixed in 6.71. The tracked 6.40 and 6.50a builds fall in the first affected range. In the tracked 6.70 build, subcommand 0x14 of IOCTL 0x8200E804 combines a caller-controlled offset with an input-buffer pointer without validating that the resulting object remains inside the request, enabling out-of-bounds kernel access.
Categories: vulnerable driver, verified
View authoritative reference β
CardIo64.sys
CardIo64.sys is a kernel driver from ICP DAS Co., LTD. (Taiwan), an industrial automation and I/O board manufacturer. The driver exposes arbitrary physical memory read/write via MmMapIoSpace, port I/O read/write (8/16/32-bit), and PCI bus data read/write via HalGetBusDataByOffset and HalSetBusDataByOffset. The driver is only 13KB and is also available in the KeServiceDescriptorTable/vulnerable-drivers repository on GitHub.
Categories: vulnerable driver, verified
View authoritative reference β
CtiIo64.sys
The driver is part of Dragon Center (or MSI Center?) from MSI. It creates \Device\CtiIo ACLless DO and provides access to memory and IO. The driver is signed with WHQL cert.
Categories: vulnerable driver, verified
View authoritative reference β
l1malwarebits.sys
l1malwarebits.sys is a vulnerable kernel driver from the KeServiceDescriptorTable/vulnerable-drivers repository. The driver exposes dangerous kernel primitives to usermode.
Categories: vulnerable driver, verified
View authoritative reference β
bedaisy.sys
BattlEye Anti-Cheat BEDAISY.SYS PPL privesc.
Categories: vulnerable driver, verified
View authoritative reference β
PSKD64.SYS
APSoft PCIScope's PSKD64 driver exposes memory-access operations through \\.\PSKD64. IOCTL 0x220044 dispatches sub-operations 0x701E and 0x701F for caller-selected virtual or physical memory reads and writes without constraining the target address. Public testing demonstrates arbitrary kernel read/write on Windows 11, including process protection removal and security-process termination.
Categories: vulnerable driver, verified
View authoritative reference β
wsftprm.sys
Northwave Cyber Security contributed this driver based on in-house research. The driver has a CVSSv3 score of 6.1, indicating a antivirus killer impact. This vulnerability could potentially be exploited for privilege escalation or other malicious activities.
Categories: vulnerable driver, verified
View authoritative reference β
ngiodriver.sys
The Carbon Black Threat Analysis Unit (TAU) discovered 34 unique vulnerable drivers (237 file hashes) accepting firmware access. Six allow kernel memory access. All give full control of the devices to non-admin users. By exploiting the vulnerable drivers, an attacker without the system privilege may erase/alter firmware, and/or elevate privileges. As of the time of writing in October 2023, the filenames of the vulnerable drivers have not been made public until now.
Categories: vulnerable driver, verified
View authoritative reference β
RtsPer.sys
The Realtek SD card reader driver, RtsPer.sys, has been found to contain multiple critical vulnerabilities (CVE-2022-25476, CVE-2022-25477, CVE-2022-25478, CVE-2022-25479, CVE-2022-25480, CVE-2024-40431, CVE-2024-40432) that allow non-privileged users to leak kernel memory, write to arbitrary kernel memory, and access physical memory via DMA. These flaws affect various SD card reader models (including RTS5227, RTS5228, RTS522A, RTS5249, RTS524A, RTS5250, RTS525A, RTS5287, RTS5260, RTS5261, RTS5264) used by major OEMs such as Dell, Lenovo, HP, and MSI. The vulnerabilities enable kernel memory leaks, arbitrary kernel memory writes, PCI configuration space manipulation, and DMA controller access from user mode. Due to the driver's widespread use, the impact is significant, potentially allowing privilege escalation and system compromise. Realtek has addressed these issues in driver version 10.0.26100.21374 or higher, released in July or August.
Categories: vulnerable driver, verified
View authoritative reference β
windivert.sys
WinDivert is a user-mode packet capture and network packet manipulation utility designed for Windows. It provides a powerful and flexible framework for intercepting, modifying, injecting, and dropping network packets at the network stack level. It operates as a lightweight, high-performance driver that interfaces directly with the network stack, allowing for detailed packet inspection and manipulation in real time.
Categories: malicious, verified
View authoritative reference β
AsrIbDrv.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, verified
View authoritative reference β
EIO.sys
This is a vulnerable driver per Microsoft.
Categories: vulnerable driver, verified
View authoritative reference β
NICM.SYS
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, verified
View authoritative reference β
AsrOmgDrv.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, verified
View authoritative reference β
SSPORT.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, verified
View authoritative reference β
filwfp.sys
Twister Antivirus, fildds.sys, DoS2
CVE-2023-1444
From IoControlCode 0x8011206B, a normal user can cause DoS due to writing into
null address.
Categories: vulnerable driver, verified
View authoritative reference β
sepdrv3_1.sys
The Carbon Black Threat Analysis Unit (TAU) discovered 34 unique vulnerable drivers (237 file hashes) accepting firmware access. Six allow kernel memory access. All give full control of the devices to non-admin users. By exploiting the vulnerable drivers, an attacker without the system privilege may erase/alter firmware, and/or elevate privileges. As of the time of writing in October 2023, the filenames of the vulnerable drivers have not been made public until now.
Categories: vulnerable driver, verified
View authoritative reference β
driver_a6deeea6.sys
Sophos, from time to time, has observed a threat actor deploy variants of Poortry on different machines within a single estate during an attack. These variants contain the same payload, but signed with a different certificate than the driver first seen used during the attack.
Categories: malicious, verified
View authoritative reference β
driver_981d03e1.sys
Sophos, from time to time, has observed a threat actor deploy variants of Poortry on different machines within a single estate during an attack. These variants contain the same payload, but signed with a different certificate than the driver first seen used during the attack.
Categories: malicious, verified
View authoritative reference β
OpenLibSys.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, verified
View authoritative reference β
PhlashNT.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, verified
View authoritative reference β
ksapi.sys
Driver can be used to load unsigned drivers
Categories: vulnerable driver, verified
View authoritative reference β
spwizimgVT.sys
Cisco Talos has identified multiple versions of an undocumented malicious driver named βRedDriver,β a driver-based browser hijacker that uses the Windows Filtering Platform (WFP) to intercept browser traffic. RedDriver has been active since at least 2021.
RedDriver utilizes HookSignTool to forge its signature timestamp to bypass Windows driver-signing policies.
Code from multiple open-source tools has been used in the development of RedDriver's infection chain, including HP-Socket and a custom implementation of ReflectiveLoader.
The authors of RedDriver appear to be skilled in driver development and have deep knowledge of the Windows operating system.
This threat appears to target native Chinese speakers, as it searches for Chinese language browsers to hijack. Additionally, the authors are likely Chinese speakers themselves.
Categories: malicious, verified
View authoritative reference β
nt6.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, unverified
View authoritative reference β
fidpcidrv.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, unverified
View authoritative reference β
hlpdrv.sys
hlpdrv.sys is a malicious driver used to disable Windows Defender by modifying registry settings. This driver has been observed in Akira ransomware campaigns, where it is deployed to facilitate AV/EDR evasion or disablement through a Bring Your Own Vulnerable Driver (BYOVD) exploitation chain. The malware modifies the DisableAntiSpyware registry key via regedit.exe execution.
Categories: malicious, verified
View authoritative reference β
sdrv_win_sliff.sys
sdrv_win_sliff.sys is a vulnerable kernel driver from the KeServiceDescriptorTable/vulnerable-drivers repository. The driver exposes dangerous kernel primitives to usermode.
Categories: vulnerable driver, verified
View authoritative reference β
WinIo64A.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, unverified
View authoritative reference β
d.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, unverified
View authoritative reference β
nvaudio.sys
The Carbon Black Threat Analysis Unit (TAU) discovered 34 unique vulnerable drivers (237 file hashes) accepting firmware access. Six allow kernel memory access. All give full control of the devices to non-admin users. By exploiting the vulnerable drivers, an attacker without the system privilege may erase/alter firmware, and/or elevate privileges. As of the time of writing in October 2023, the filenames of the vulnerable drivers have not been made public until now.
Categories: vulnerable driver, verified
View authoritative reference β
ZYArKit.sys
V-secure ZYArKit.sys version 2.0.13.5 is a signed kernel driver assessed in public KOSEC BYOVD research. KOSEC documents an IOCTL path that references a user-supplied process handle and reaches ZwTerminateProcess, allowing administrator-context termination of non-protected processes from kernel mode.
Categories: vulnerable driver, verified
View authoritative reference β
driver_89036534.sys
Sophos, from time to time, has observed a threat actor deploy variants of Poortry on different machines within a single estate during an attack. These variants contain the same payload, but signed with a different certificate than the driver first seen used during the attack.
Categories: malicious, verified
View authoritative reference β
HwRwDrv.sys
Hardware read/write driver signed by a revoked Certum certificate (Open Source Developer, Jun Liu). Provides arbitrary physical memory read/write and PCI bus data access. Identified in ESET EDR killers research (March 2026) with 174 execution parents indicating widespread abuse by threat actors to disable EDR products.
Categories: vulnerable driver, verified
View authoritative reference β
TBT_Force_Power_Control_Access64.sys
TBT_Force_Power_Control_Access64.sys is a Thunderbolt force power control driver from Wistron Corporation that exposes physical memory read/write via MmMapIoSpace. Wistron is a major Taiwan-based OEM/ODM. Another Wistron driver (WiRwaDrv.sys) is already tracked in LOLDrivers. The driver is available in the KeServiceDescriptorTable/vulnerable-drivers repository.
Categories: vulnerable driver, verified
View authoritative reference β
nt4.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, unverified
View authoritative reference β
mlgbbiicaihflrnh.sys
Confirmed vulnerable driver from Microsoft Block List
Categories: malicious, verified
View authoritative reference β
driver_0a636606.sys
Sophos, from time to time, has observed a threat actor deploy variants of Poortry on different machines within a single estate during an attack. These variants contain the same payload, but signed with a different certificate than the driver first seen used during the attack.
Categories: malicious, verified
View authoritative reference β
bandai.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, unverified
View authoritative reference β
be6318413160e589080df02bb3ca6e6a.sys
Cisco Talos has identified multiple versions of an undocumented malicious driver named βRedDriver,β a driver-based browser hijacker that uses the Windows Filtering Platform (WFP) to intercept browser traffic. RedDriver has been active since at least 2021. RedDriver utilizes HookSignTool to forge its signature timestamp to bypass Windows driver-signing policies. Code from multiple open-source tools has been used in the development of RedDriver's infection chain, including HP-Socket and a custom implementation of ReflectiveLoader. The authors of RedDriver appear to be skilled in driver development and have deep knowledge of the Windows operating system. This threat appears to target native Chinese speakers, as it searches for Chinese language browsers to hijack. Additionally, the authors are likely Chinese speakers themselves.
Categories: malicious, verified
View authoritative reference β
driver_ef9d653a.sys
Sophos, from time to time, has observed a threat actor deploy variants of Poortry on different machines within a single estate during an attack. These variants contain the same payload, but signed with a different certificate than the driver first seen used during the attack.
Categories: malicious, verified
View authoritative reference β
cpupress.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, unverified
View authoritative reference β
ProcessCtr.sys
EsafeNet ProcessCtr / ProcessCtrl64.sys creates a device object reachable by local callers and exposes process-control IOCTL paths. Public research documents a vulnerable process-termination path that can allow privileged process termination or denial of service when user-supplied context/handle material is accepted without adequate authorization checks.
Categories: vulnerable driver, verified
View authoritative reference β
ksapi.sys
Driver can be used to load unsigned drivers
Categories: vulnerable driver, verified
View authoritative reference β
nvflsh32.sys
Confirmed vulnerable driver from Microsoft Block List
Categories: vulnerable driver, verified
View authoritative reference β
HpPortIox64.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, verified
View authoritative reference β
GPU-Z.sys
Utilized in RealBlindingEDR.
Categories: vulnerable driver, verified
View authoritative reference β
asio.sys
ASUS AsIO hardware-access drivers expose physical-memory mapping and I/O-port operations to user mode. These primitives can be abused to read or modify privileged system state and execute code in kernel context.
Categories: vulnerable driver, verified
View authoritative reference β
PCHunter.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, unverified
View authoritative reference β
yyprotect64.sys
Confirmed vulnerable driver from Microsoft Block List
Categories: vulnerable driver, verified
View authoritative reference β
directio32_legacy.sys
Confirmed vulnerable driver from Microsoft Block List
Categories: vulnerable driver, verified
View authoritative reference β
inpoutx64.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, verified
View authoritative reference β
iobios64.sys
iobios64.sys is a vulnerable kernel driver from the KeServiceDescriptorTable/vulnerable-drivers repository. The driver exposes dangerous kernel primitives to usermode.
Categories: vulnerable driver, verified
View authoritative reference β
kprocesshacker.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, verified
View authoritative reference β
VdBSv64.sys
The Carbon Black Threat Analysis Unit (TAU) discovered 34 unique vulnerable drivers (237 file hashes) accepting firmware access. Six allow kernel memory access. All give full control of the devices to non-admin users. By exploiting the vulnerable drivers, an attacker without the system privilege may erase/alter firmware, and/or elevate privileges. As of the time of writing in October 2023, the filenames of the vulnerable drivers have not been made public until now.
Categories: vulnerable driver, verified
View authoritative reference β
b1.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, unverified
View authoritative reference β
TSDRVX64.sys
Northwave Cyber Security identified TSDRVX64 as a local privilege-escalation vulnerability with a CVSSv3 score of 8.8. Successful exploitation provides kernel-level impact and may enable an attacker to disable security controls or tamper with the operating system.
Categories: vulnerable driver, verified
View authoritative reference β
msr.sys
Identified on the MSFT Driver Block list, non-admin can write MSR.
Categories: vulnerable driver, verified
View authoritative reference β
mimikatz.sys
Confirmed vulnerable driver from Microsoft Block List
Categories: malicious, verified
View authoritative reference β
AsrAutoChkUpdDrv_1_0_32.sys
Confirmed vulnerable driver from Microsoft Block List
Categories: vulnerable driver, verified
View authoritative reference β
bwrs.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, unverified
View authoritative reference β
a26363e7b02b13f2b8d697abb90cd5c3.sys
Cisco Talos has identified multiple versions of an undocumented malicious driver named βRedDriver,β a driver-based browser hijacker that uses the Windows Filtering Platform (WFP) to intercept browser traffic. RedDriver has been active since at least 2021. RedDriver utilizes HookSignTool to forge its signature timestamp to bypass Windows driver-signing policies. Code from multiple open-source tools has been used in the development of RedDriver's infection chain, including HP-Socket and a custom implementation of ReflectiveLoader. The authors of RedDriver appear to be skilled in driver development and have deep knowledge of the Windows operating system. This threat appears to target native Chinese speakers, as it searches for Chinese language browsers to hijack. Additionally, the authors are likely Chinese speakers themselves.
Categories: malicious, verified
View authoritative reference β
bw.sys
vulnerable driver documented by LOLDrivers.
Categories: vulnerable driver, unverified
View authoritative reference β
EnPortv.sys
Guidance Software EnPortv.sys is an older EnCase kernel driver documented in KOSEC BYOVD research and in public reporting on signed forensic drivers used by EDR-killer tooling. KOSEC documents a KillProc IOCTL path that can terminate a target process when called from an administrator context with the expected caller PID material.
Categories: vulnerable driver, verified
View authoritative reference β
unknown.sys
unknown.sys is an unattributed signed kernel driver documented in public UnknownKiller / BlackSnufkin BYOVD research. The public PoCs identify the driver as exposing a process-kill primitive suitable for BYOVD process termination research.
Categories: vulnerable driver, verified
View authoritative reference β
srswdrv.sys
srswdrv.sys is a vulnerable kernel driver from the KeServiceDescriptorTable/vulnerable-drivers repository. The driver exposes dangerous kernel primitives to usermode.
Categories: vulnerable driver, verified
View authoritative reference β
HardwareMon-x86.sys
HardwareMon-x86.sys is a vulnerable kernel driver from the KeServiceDescriptorTable/vulnerable-drivers repository. The driver exposes dangerous kernel primitives to usermode.
Categories: vulnerable driver, verified
View authoritative reference β