Skip to content
BYOVD Technique Enables Attackers to Disable Security Tools

BYOVD Technique Enables Attackers to Disable Security Tools

First seen 1 Jul 2026, 12:12 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •July 2, 2026 at 11:42 UTC
  • •BYOVD exploits trusted Windows drivers to disable security tools.
  • •Hundreds of vulnerable drivers are actively used in ransomware campaigns.
  • •Microsoft's kernel hardening measures are insufficient against BYOVD attacks.

Attackers are increasingly using the Bring Your Own Vulnerable Driver (BYOVD) technique to disable antivirus (AV) and endpoint detection and response (EDR) tools. This method exploits flaws in trusted Windows drivers, allowing attackers to operate at the highest privilege level within the Windows kernel. Hundreds of vulnerable drivers are in circulation, with new ones being discovered regularly. The technique has become a standard part of modern ransomware campaigns, enabling attackers to blind or cripple security software. The Symantec Threat Hunter Team's whitepaper highlights the ineffectiveness of Microsoft's kernel hardening against these attacks. Attackers can either kill security processes or strip them of necessary rights, leaving systems vulnerable. The BYOVD technique has been bundled into ransomware-as-a-service (RaaS) offerings, increasing its accessibility for cybercriminals.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 100d ago How this analysis works

Timeline

2026-06-30
Symantec releases whitepaper on defense evasion
The Symantec Threat Hunter Team published a whitepaper detailing the BYOVD technique and its implications for security.
Security
Recent
BYOVD technique identified as a growing threat
The BYOVD technique has rapidly become standard in ransomware campaigns, allowing attackers to disable AV and EDR tools.
Cybersecuritynews

More articles in this cluster (2)

Following this threat?

Track Poortry in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed