Bypass Record

BYOVD (Vulnerable Driver) × CrowdStrike Falcon

A publicly-reported instance of BYOVD (Vulnerable Driver) bypassing CrowdStrike Falcon, recorded with its original source. Factual record; no assessment of any specific deployment.

Product
CrowdStrike Falcon
Technique
BYOVD (Vulnerable Driver)
MITRE ATT&CK
T1562.001
Confidence
High
Severity
Critical
Status
poc
Disclosed
2026-08-26
Config / version noted
Not stated

Provenance

Reported as

SPECTRE Backdoor blinds CrowdStrike and SentinelOne at the kernel level without terminating the EDR processes

Mechanism

SPECTRE Backdoor uses a vulnerable driver to gain kernel-level access and then manipulates kernel structures (such as callback arrays or ETW providers) to blind the EDR without terminating its processes. This defeats the EDR's ability to detect malicious activity while the agent appears to be functioning normally.

Detection & mitigation

Monitor for loading of known vulnerable drivers (BYOVD) using driver block rules and integrity checks. Deploy kernel-level telemetry (e.g., ETW, driver events) to detect tampering with EDR callbacks or structures. Enforce least privilege to limit driver installation.

BYOVD (Vulnerable Driver) has also been recorded against

This is a record of a publicly-reported event, not an assessment of any specific organization's deployment. Detection and mitigation notes are drawn from the cited source. Where the source is silent, fields are omitted.