BYOVD research use cases featuring vulnerable driver discovery and reverse engineering methodology. (CVE-2025-52915, CVE-2025-1055, CVE-2026-3609, CVE-2026-8501).
-
Updated
Aug 18, 2026 - Rust
BYOVD research use cases featuring vulnerable driver discovery and reverse engineering methodology. (CVE-2025-52915, CVE-2025-1055, CVE-2026-3609, CVE-2026-8501).
BYOVD hunter to help prioritize windows drivers worth manual analysis
A BYOVD PoC exploitation Alinubx.sys to terminate Windows processes.
DriverTrust Auditor is a no-kernel, PySide6 GUI that inventories Windows drivers, batch-resolves FileVersion/Authenticode/WHQL/SHA-256, and scores risk. It reads active WDAC/HVCI posture, simulates “what-if” enforcement, scans offline .sys trees, and cross-references LOLDrivers for BYOVD
LOLDrivers YARA Rule Generator
Living off the Land LOLBins MCP Server — 59 composite tools for LOL binary intelligence across 10 catalogs (GTFOBins, LOLBAS, LOOBins, LOLDrivers, LOLRMM, LOLESXi, LOTP, LOLC2, LOFLCAB, WADComs)
A simple writeup of an driver found in the LOLDrivers repository.
A small but quite to-the-point vulnerable driver!
List of POCs I have done for some of the LOLDrivers.
Download all vulnerable drivers from LOLDrivers
File hash databases for digital forensics — NSRL/CIRCL known-good, malware known-bad, known-vulnerable Windows drivers (loldrivers), and analyst-supplied MD5/SHA1/SHA256 feeds.
To associate your repository with the loldrivers topic, visit your repo's landing page and select "manage topics."