BYOVD research use cases featuring vulnerable driver discovery and reverse engineering methodology. (CVE-2025-52915, CVE-2025-1055, CVE-2026-3609, CVE-2026-8501).
-
Updated
Jul 12, 2026 - Rust
BYOVD research use cases featuring vulnerable driver discovery and reverse engineering methodology. (CVE-2025-52915, CVE-2025-1055, CVE-2026-3609, CVE-2026-8501).
BYOVD hunter to help prioritize windows drivers worth manual analysis
DriverTrust Auditor is a no-kernel, PySide6 GUI that inventories Windows drivers, batch-resolves FileVersion/Authenticode/WHQL/SHA-256, and scores risk. It reads active WDAC/HVCI posture, simulates “what-if” enforcement, scans offline .sys trees, and cross-references LOLDrivers for BYOVD
A simple writeup of an driver found in the LOLDrivers repository.
Living off the Land LOLBins MCP Server — 59 composite tools for LOL binary intelligence across 10 catalogs (GTFOBins, LOLBAS, LOOBins, LOLDrivers, LOLRMM, LOLESXi, LOTP, LOLC2, LOFLCAB, WADComs)
List of POCs I have done for some of the LOLDrivers.
Download all vulnerable drivers from LOLDrivers
File hash databases for digital forensics — NSRL/CIRCL known-good, malware known-bad, known-vulnerable Windows drivers (loldrivers), and analyst-supplied MD5/SHA1/SHA256 feeds.
Add a description, image, and links to the loldrivers topic page so that developers can more easily learn about it.
To associate your repository with the loldrivers topic, visit your repo's landing page and select "manage topics."