Stop BYOVD attacks

Prevent vulnerable-driver exploitation in the Windows kernel.

Attackers can load a legitimately signed but vulnerable driver, exploit it from user mode, and obtain the kernel-level capabilities needed to disable endpoint defenses. Ranger prevents this exploitation, including when the driver is not yet present on a blocklist.

Autonomous, on-device hardening without signatures, cloud dependency, or vulnerable-driver blocklists.
BYOVD execution sequence Vulnerable-driver exploitation blocked
Process context Attacker-controlled process in user mode
Kernel driver loaded Legitimately signed but vulnerable driver
Security components targeted EDR, AV, security logging, or kernel callbacks
Prevention result Exploit attempt blocked
Known + unknown driversPrevent vulnerable-driver exploitation without waiting for a blocklist update.
Zero ongoing rule maintenanceApply protection on-device without signatures or continuous policy tuning.
Strengthen existing defensesEnhance tamper protection for established third-party endpoint security products.
Driver-signing limitation

A signed driver can still contain an exploitable kernel interface.

A digital signature confirms a driver's publisher and integrity; it does not verify that every privileged operation the driver exposes is secure. If the driver contains a vulnerable interface, an attacker can use it to perform kernel operations that are unavailable to an ordinary user-mode process.

Driver validation

A valid signature does not guarantee driver security.

Windows uses digital signatures to verify a driver's publisher and integrity before loading it. A correctly signed driver can still expose a vulnerable interface that allows an attacker-controlled process to perform privileged kernel operations.

Why Windows allows it

The driver passes loading checks

The driver may come from a graphics, audio, antivirus, disk, or monitoring product and carry a valid signature. Windows and conventional allowlists recognize it as legitimate software installed through standard mechanisms.

  • Valid publisher signature and intact driver package
  • Loaded through standard Windows driver mechanisms
  • Not yet identified on a vulnerable-driver blocklist
What the attacker exploits

The driver exposes privileged operations

From user mode, the attacker calls the driver's vulnerable interface to perform privileged kernel operations. That capability can be used to terminate security processes, remove callbacks, suppress logging, or prepare the system for an undetected payload.

  • EDR, antivirus, security logging, and tamper protection
  • Kernel memory access or arbitrary kernel-level execution
  • Deploy ransomware, exfiltration tools, or persistent backdoors
How BYOVD works

How a signed driver becomes a kernel-level threat.

A BYOVD attack follows a clear sequence: introduce a vulnerable signed driver, load it, exploit the exposed interface, and tamper with endpoint security. Ranger blocks the exploitation attempt before the attacker obtains kernel-level privileges.

01 / INTRODUCE

Introduce the driver

After compromising an endpoint through phishing, stolen credentials, or an exposed service, the attacker writes a legitimate but vulnerable driver to the system.

02 / LOAD

Load the signed driver

The attacker uses standard installation mechanisms to load the signed driver. Because its signature is valid, the operating system may allow it into the kernel.

03 / EXPLOIT

Exploit the vulnerable interface

An attacker-controlled process calls the driver's vulnerable interface to gain privileged operations that are normally unavailable from user mode.

04 / TAMPER

Disable security controls

With kernel-level privileges, the attacker can disable endpoint protection, suppress telemetry, establish persistence, and deploy ransomware or other payloads after security controls are disabled.

Vulnerable-driver prevention

Prevent BYOVD from granting kernel-level privileges.

Ranger does not depend on a driver being discovered, reported, and added to a blocklist. It prevents the kernel-level exploitation used by BYOVD attacks, including drivers not yet identified as vulnerable.

01

Identify BYOVD activity

Ranger evaluates attempts by user-mode processes to access sensitive kernel capabilities, independent of the specific driver name, hash, or public vulnerability record.

02

Prevent privileged abuse

It prevents an attacker from using a vulnerable signed driver to obtain the kernel-level privileges needed to tamper with security software or system behavior.

03

Preserve endpoint defenses

EDR, antivirus, logging, and other endpoint controls remain active, preserving the visibility and response capability the rest of the security stack relies on.

Driver evaluation

Evaluate driver behavior in addition to its signature.

A signature identifies the publisher, while a blocklist identifies drivers already known to be vulnerable. Neither identifies an undisclosed vulnerability. Ranger prevents attempts to obtain privileged kernel capabilities without requiring prior knowledge of the driver.

This protection works alongside existing endpoint security rather than replacing it. Ranger adds kernel-level tamper protection for products such as CrowdStrike, Microsoft Defender, SentinelOne, and others without requiring a separate vulnerable-driver list.

Example driver decision
DriverSigned third-party kernel driverKnown
CapabilityVulnerable privileged interface exposed to user modeRisk
BehaviorAttacker attempts to disable an endpoint defenseUnsafe
OutcomeKernel abuse preventedBlocked
Protection model

Kernel hardening against vulnerable-driver exploitation.

Ranger prevents BYOVD exploitation while preserving the endpoint tools and operational model already in place.

Prevent vulnerable-driver exploitationBlock attempts to obtain kernel-level privileges through vulnerable signed drivers.
Protection independent of blocklistsProtect against known and unknown vulnerable drivers without waiting for public disclosure.
Compatible with existing endpoint securityStrengthen third-party tamper protection without replacing the customer's EDR or antivirus platform.
Autonomous on-device protectionOperate without cloud lookups, signatures, or continuous policy and list maintenance.
Common questions

What you need to know.

Clear answers about how Ranger handles vulnerable drivers, works with your existing endpoint security, and prevents privileged abuse.

How is this different from a vulnerable-driver blocklist?

A blocklist can stop drivers that have already been identified and included in an update. Ranger prevents vulnerable-driver exploitation even when a driver is unknown, newly disclosed, or not yet present on a blocklist.

Does Ranger replace our existing endpoint security?

No. Ranger works alongside existing security solutions and adds kernel-level tamper protection. It strengthens tamper resistance for products including CrowdStrike, Microsoft Defender, SentinelOne, Sophos, and Sysmon.

What happens when a driver is used for privileged abuse?

Ranger blocks the attempt to obtain kernel-level privileges before the attacker can disable endpoint defenses. Existing security tools remain active to alert, investigate, isolate, and respond to the original compromise.

Take the next step

Prevent exploitation of trusted, vulnerable drivers.

See how Ranger prevents BYOVD attacks and strengthens the endpoint defenses you already use.