Bleepingcomputer
Attackers Exploit Vulnerable Windows Driver to Disable EDR Tools
First seen 5 Feb 2026, 18:32 UTC
•


•79% similarity
•50.9
•Analyst Insight
Share:
Export
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Browse articles
In early February 2026, attackers exploited a decade-old vulnerability in a Guidance Software EnCase kernel driver to disable endpoint detection and response (EDR) tools during a network intrusion. They gained access through compromised SonicWall SSLVPN credentials and used the Bring Your Own Vulnerable Driver (BYOVD) technique to terminate security processes. The attack was halted before ransomware could be deployed.
ThreatCluster AI
How this analysis works