Bring Your Own Vulnerable Driver - MITRE ATT&CK

Threat entity extracted from intelligence sources

Frequency
1
occurrences
First Seen
December 11, 2025
Last Seen
December 11, 2025

Bring Your Own Vulnerable Driver (BYOVD) is a MITRE ATT&CK technique in which adversaries load a vulnerable or unsigned driver to run code in kernel space, enabling privilege escalation and stealth.

Bring Your Own Vulnerable Driver is a mitre_attack tracked across 1 threat cluster and 1 intelligence report mention on ThreatCluster. First observed December 11, 2025; most recent activity December 11, 2025.

Overview

Bring Your Own Vulnerable Driver (BYOVD) is a MITRE ATT&CK technique in which adversaries load a vulnerable or unsigned driver to run code in kernel space, enabling privilege escalation and stealth. It is significant because kernel-level execution allows attackers to bypass many endpoint protections and conceal malicious activity, a tactic leveraged by ransomware such as DeadLock to evade detection and enhance impact.

Related Threat Clusters

  • DeadLock Ransomware Employs BYOVD Technique to Bypass Security

    DeadLock ransomware is being deployed by a financially motivated threat actor using a new loader that utilizes the Bring Your Own Vulnerable Driver (BYOVD) technique. This method disables endpoint detection and response…

    3 articles · Updated December 10, 2025

Recent Intelligence Reports

  • BYOVD enhances DeadLock ransomware's stealth — Scworld · December 11, 2025

Frequently asked questions

What is Bring Your Own Vulnerable Driver?

Bring Your Own Vulnerable Driver (BYOVD) is a MITRE ATT&CK technique in which adversaries load a vulnerable or unsigned driver to run code in kernel space, enabling privilege escalation and stealth.

Is Bring Your Own Vulnerable Driver still active?

The most recent intelligence report mentioning Bring Your Own Vulnerable Driver on ThreatCluster is dated December 11, 2025.

What is Bring Your Own Vulnerable Driver associated with?

Across ThreatCluster reporting, Bring Your Own Vulnerable Driver most frequently co-occurs with Ransomware, CVE-2024-51324, DeadLock, Baidu Antivirus, Windows, among 6 tracked related entities.

What are the latest developments involving Bring Your Own Vulnerable Driver?

The most significant recent cluster is “DeadLock Ransomware Employs BYOVD Technique to Bypass Security” (3 articles · Updated December 10, 2025). Bring Your Own Vulnerable Driver appears across 1 threat cluster in total, listed above with sources.

How much reporting does ThreatCluster have on Bring Your Own Vulnerable Driver?

Bring Your Own Vulnerable Driver appears in 1 intelligence report mention across 1 deduplicated threat cluster, aggregated from 17,000+ monitored sources.

CVSS v3.1 Breakdown