Attackers Exploit Vulnerable Windows Driver to Disable EDR Tools

Attackers Exploit Vulnerable Windows Driver to Disable EDR Tools

First seen 5 Feb 2026, 18:32 UTC BleepingcomputerHuntressCsoonlineScworld 79% similarity 50.9 Analyst Insight

Article Content

Browse articles
ThreatCluster

In early February 2026, attackers exploited a decade-old vulnerability in a Guidance Software EnCase kernel driver to disable endpoint detection and response (EDR) tools during a network intrusion. They gained access through compromised SonicWall SSLVPN credentials and used the Bring Your Own Vulnerable Driver (BYOVD) technique to terminate security processes. The attack was halted before ransomware could be deployed.

ThreatCluster AI How this analysis works

Community

Browse all →

Tracked Entities in This Story