byovd
Here are 64 public repositories matching this topic...
BYOVD research use cases featuring vulnerable driver discovery and reverse engineering methodology. (CVE-2025-52915, CVE-2025-1055, CVE-2026-3609, CVE-2026-8501).
-
Updated
Aug 18, 2026 - Rust
🤖 Kill The Protected Process 🤖
-
Updated
May 29, 2024 - Rust
KslDump — Why bring your own knife when Defender already left one in the kitchen?
-
Updated
Apr 13, 2026 - Python
Another BYOVD process killer. works on all EDR's. fully signed.
-
Updated
May 19, 2026 - C++
「💀」Proof of concept on BYOVD attack
-
Updated
Dec 7, 2024 - C++
BYOVD hunter to help prioritize windows drivers worth manual analysis
-
Updated
Aug 19, 2025 - Rust
BYOVD tool for manipulating Windows Protected Process Light (PPL) protection at the kernel level.
-
Updated
May 25, 2026 - C
DSE & PG bypass via BYOVD attack
-
Updated
Jul 12, 2025 - C++
Advanced PoC & Research for CVE-2026-0828 (Safetica) and CVE-2025-7771 (ThrottleStop). Analysis of BYOVD (Bring Your Own Vulnerable Driver) TTPs for Ring 0 process termination and physical memory R/W. Researching EDR-Killer patterns, PPL bypasses, and kernel-mode primitives used by MedusaLocker and other threat actors.
-
Updated
Feb 4, 2026 - C
Kernel-mode process terminator using a signed BYOVD driver. Works on all Windows 10/11. No offsets, no PDB. Rust.
-
Updated
Sep 3, 2026 - Rust
「
-
Updated
Dec 7, 2024 - C++
CVE-2026-36425 OPSWAT AppRemover (ardrv.sys) improper access control advisory
-
Updated
Jul 17, 2026 - C++
A BYOVD technique abuse tool
-
Updated
Jul 21, 2026 - Rust
Pure-Go offensive-security primitives library: syscalls, evasion (AMSI/ETW/unhook/sleepmask), injection, PE packer, credentials, post-ex, C2. MITRE ATT&CK mapped. Authorized research only.
-
Updated
Jul 13, 2026 - Go
📟 a tiny code that performs kernel-mode read/write using CVE-2023-38817.
-
Updated
Mar 28, 2025 - C++
Add this topic to your repo
To associate your repository with the byovd topic, visit your repo's landing page and select "manage topics."