Index / Techniques / BYOVD (Vulnerable Driver)
Technique Record · T1562.001

BYOVD (Vulnerable Driver)

Publicly-reported instances of BYOVD (Vulnerable Driver) bypassing endpoint security products. Maintained on the same basis for every technique in the Index.

70
recorded bypasses
28
products affected

Products recorded as bypassed by BYOVD (Vulnerable Driver)

ProductEntriesHigh-confidenceMost recent
Microsoft 24232026-05-03
SentinelOne 542026-03-26
CrowdStrike 432026-04-05
Elastic 322025-11-21
Palo Alto Networks 332026-02-10
Sophos 222023-08-16
Kaspersky 212026-03-26
Carbon Black 222025-07-31
Symantec 212025-08-07
McAfee 212025-08-07
Webroot 212025-08-07
Cylance 212025-08-07
Zemana 222024-03-14
Fortinet 112026-02-04
EasyAntiCheat 112023-11-05
Easy Anti-Cheat 112024-07-24
BattlEye 112024-07-24
Baidu 112026-01-26
F-Secure 102025-08-07
HitmanPro 102025-08-07
Various EDR vendors 112026-05-03
targeted EDR vendor 102024-09-13
Bitdefender 102025-08-07
Riot Games 112025-03-02
Cortex 112023-05-31
other EDR vendors 102024-09-18
Avast 112024-09-21
Trend Micro 102025-08-07

All entries

ProductConfidenceDisclosedSource
Microsoft high 2026-05-03lyrie.ai record →
Various EDR vendors high 2026-05-03lyrie.ai record →
CrowdStrike high 2026-04-05threatlabsnews.xcitium.com record →
Microsoft high 2026-03-26github.com record →
Microsoft high 2026-03-26labs.cloudsecurityalliance.org record →
Kaspersky high 2026-03-26labs.cloudsecurityalliance.org record →
SentinelOne high 2026-03-26labs.cloudsecurityalliance.org record →
Microsoft high 2026-03-13www.healthcaredive.com record →
Microsoft high 2026-02-24blog.silentforce.io record →
SentinelOne high 2026-02-24blog.silentforce.io record →
CrowdStrike high 2026-02-24blog.silentforce.io record →
Microsoft high 2026-02-10github.com record →
Palo Alto Networks high 2026-02-10www.gblock.app record →
CrowdStrike high 2026-02-10www.gblock.app record →
Fortinet high 2026-02-04cybersecuritynews.com record →
Baidu high 2026-01-26the-hunters-ledger.com record →
Elastic high 2025-11-21ashes-cybersecurity.com record →
Microsoft high 2025-11-14gbhackers.com record →
Microsoft high 2025-11-10github.com record →
Microsoft high 2025-11-07github.com record →
Microsoft high 2025-08-28radar.offseq.com record →
Elastic medium 2025-08-16cybersecuritynews.com record →
Microsoft medium 2025-08-07mine2.io record →
Kaspersky medium 2025-08-07mine2.io record →
Trend Micro medium 2025-08-07mine2.io record →
SentinelOne medium 2025-08-07mine2.io record →
McAfee medium 2025-08-07mine2.io record →
Bitdefender medium 2025-08-07mine2.io record →
Cylance medium 2025-08-07mine2.io record →
F-Secure medium 2025-08-07mine2.io record →
Symantec medium 2025-08-07mine2.io record →
Webroot medium 2025-08-07mine2.io record →
HitmanPro medium 2025-08-07mine2.io record →
Carbon Black high 2025-07-31cybersecuritynews.com record →
McAfee high 2025-05-30threatlabsnews.xcitium.com record →
Webroot high 2025-05-30threatlabsnews.xcitium.com record →
CrowdStrike medium 2025-05-30threatlabsnews.xcitium.com record →
Microsoft high 2025-05-30threatlabsnews.xcitium.com record →
Microsoft high 2025-03-16asec.ahnlab.com record →
Riot Games high 2025-03-02github.com record →
Microsoft high 2025-01-18www.zerosalarium.com record →
Palo Alto Networks high 2024-11-01unit42.paloaltonetworks.com record →
Avast high 2024-09-21github.com record →
other EDR vendors medium 2024-09-18cybersecuritynews.com record →
Microsoft high 2024-09-18cybersecuritynews.com record →
targeted EDR vendor medium 2024-09-13www.levelblue.com record →
Microsoft high 2024-08-18github.com record →
Easy Anti-Cheat high 2024-07-24github.com record →
BattlEye high 2024-07-24github.com record →
SentinelOne high 2024-07-16trustedsec.com record →
Symantec high 2024-07-16trustedsec.com record →
Microsoft high 2024-07-16trustedsec.com record →
Elastic high 2024-06-27infosecwriteups.com record →
Microsoft high 2024-06-27infosecwriteups.com record →
Microsoft high 2024-05-27github.com record →
Microsoft high 2024-04-05github.com record →
Microsoft high 2024-04-04github.com record →
Zemana high 2024-03-14www.sentinelone.com record →
Microsoft high 2024-01-12www.trendmicro.com record →
EasyAntiCheat high 2023-11-05github.com record →
Palo Alto Networks high 2023-09-22securityonline.info record →
Microsoft high 2023-08-16jmp-esp.org record →
Sophos high 2023-08-16jmp-esp.org record →
Zemana high 2023-06-15voidsec.com record →
SentinelOne high 2023-05-31www.bleepingcomputer.com record →
Cylance high 2023-05-31www.bleepingcomputer.com record →
Microsoft high 2023-05-31www.bleepingcomputer.com record →
Cortex high 2023-05-31www.bleepingcomputer.com record →
Carbon Black high 2023-05-31www.bleepingcomputer.com record →
Sophos high 2023-05-31www.bleepingcomputer.com record →

Counts reflect distinct publicly-reported events on record; absence of an entry means no confirmed public report is on file.