Bypass Record
BYOVD (Vulnerable Driver) × SentinelOne
A publicly-reported instance of BYOVD (Vulnerable Driver) bypassing SentinelOne, recorded with its original source. Factual record; no assessment of any specific deployment.
Reported as
The technique bypasses EDR hooks, PPL, and monitoring by operating on a copy, leveraging BYOVD to disable PPL in kernel memory.
Mechanism
Doppelganger clones the LSASS process using NtCreateProcessEx after disabling PPL via a signed vulnerable driver (RTCore64.sys) that writes to the EPROCESS structure in kernel memory. It resolves APIs dynamically from clean DLLs to avoid IAT scanning, steals a SYSTEM token from winlogon.exe for privileges, and then dumps credentials from the clone, which lacks EDR hooks and PPL.
This is a record of a publicly-reported event, not an assessment of any specific organization's deployment. Detection and mitigation notes are drawn from the cited source. Where the source is silent, fields are omitted.