LOLDrivers Documentation
repository·main·Indexed 23 days ago
https://github.com/magicsword-io/loldriversA centralized repository of vulnerable and malicious Windows drivers. It provides detection rules (Sigma, Yara, ClamAV, Sysmon, and WDAC), scanning tools, and data generators to help organizations secure infrastructure against driver-based attacks. Includes tools for YARA rule generation, Lacework LQL detection creation, and blocklist analysis against the Microsoft Vulnerable Driver Blocklist.
What's inside LOLDrivers
- LOLDrivers (Living Off The Land Drivers) is an open-source repository that aggregates vulnerable, malicious, and known malicious Windows drivers. It is designed to help organizations identify and mitigate driver-related security risks by providing categorized driver information and detection rules (Sigma, Yara, ClamAV, Sysmon, and WDAC).
Overview of BdApiUtil.sys
mainBdApiUtil.sys is a vulnerable driver that can be used to load unsigned drivers. It includes an IOCTL code that accepts a PID and terminates that process (arbitrary process termination).
Key Details:
- UUID:
708650ed-c497-48be-97bc-9edd48cf2a1a - Privileges: Requires Admin privileges to install, but once installed, it can be called by any user (non-admin).
- Use Case: Privilege escalation.
- Operating System: Windows 10.
- UUID:
Overview of KmWpsMs.sys vulnerable driver
mainKmWpsMs.sys is a vulnerable kernel driver from the KeServiceDescriptorTable/vulnerable-drivers repository. It exposes dangerous kernel primitives to usermode, which can be used to elevate privileges on Windows 10 systems.
- UUID:
a6340f12-b0ee-41c5-acf0-92be886d1296 - Author: Michael Haag
- Use Case: Elevate privileges
- Privileges Required: kernel
- Operating System: Windows 10
- UUID:
mhyprotrpg.Sys Driver Details
mainThe
mhyprotrpg.Sysdriver is a confirmed vulnerable driver included in the Microsoft Block List. It is used for privilege escalation in Windows environments.Core Metadata:
- UUID:
ebdde780-e142-44e7-a998-504c516f4695 - Use Case: Elevate privileges
- Privileges: kernel
- Operating System: Windows
- UUID:
Details for psmounterex.sys driver
mainThe
psmounterex.sysdriver (UUID:0f64bf7a-2ef2-45ea-af7d-4e7c87d98777) is a vulnerable driver contributed by Northwave Cyber Security. It has a CVSSv3 score of 8.8, indicating a high impact for privilege escalation.Usage Profile:
- Use Case: Elevate privileges
- Privileges Required: kernel
- Operating System: Windows 10
Vulnerable Sample Info:
- Filename:
psmounterex.sys - Product: PSMounterEx
- Company: Windows (R) Win 7 DDK provider
- MD5:
2a9cf32ba325f394ae1cfb1e70f38b6e - SHA256:
4e99d454a56845bb0e622cfd68b895b7868ef7e8a43424e5b7b803f5a2d25eca
CcProtect.sys Driver Overview
mainCnCrypt
CcProtect.sysis a signed kernel driver used in BlackSnufkin BYOVD (Bring Your Own Vulnerable Driver) research as a process-killer provider.Warning: Using this driver may cause system instability if HVCI (Hypervisor-Protected Code Integrity) is enabled. It is recommended to disable HVCI to avoid crashes.
- UUID:
3e3067b0-3d74-46fe-9f57-1ae3a0293958 - Use Case: Terminate processes from kernel mode through a vulnerable driver path.
- Privileges Required:
kernel - Supported OS: Windows 10, Windows 11
- UUID:
Identify xjokercontroller.sys vulnerability details
mainThe
xjokercontroller.sysdriver is a confirmed vulnerable driver from the Microsoft Block List. It is primarily used for elevating privileges in a Windows environment with kernel level access.Metadata:
- UUID:
b3fd8560-79d3-40b7-b05f-c78044176c8c - Created: 2023-07-22
- Author: Michael Haag
- UUID:
DirectIo.sys Driver Information
mainDirectIo.sys is a vulnerable kernel driver used for privilege escalation on Windows 10.
Metadata:
- UUID:
62e2a967-1f03-4225-a325-122b109208f3 - Author: Nasreddine Bencherchali
- Created: 2023-05-06
- Use Case: Elevate privileges
- Privileges Required: kernel
- Operating System: Windows 10
- Imports:
ntoskrnl.exe,HAL.dll
- UUID:
Vulnerability details for mhyprotnap.sys
mainThe
mhyprotnap.sysdriver is a confirmed vulnerable driver from the Microsoft Block List. It can be used to elevate privileges to kernel level on Windows operating systems.Driver Metadata:
- UUID:
75a66604-f024-4f11-8ba7-fdd64a0df3bf - Created: 2023-07-22
- Author: Michael Haag
- UUID:
Analyze the malicious.sys driver (UUID: 3e5c0fc4-bfe8-4af2-9613-4f56b0e3c2c8)
mainThe
malicious.sysdriver is a demonstration tool used to showcase the abuse ofRTCore64.sys(CVE-2019-16098) from MSI and the nullification of the DSE (Driver Signature Enforcement) flag to load unsigned drivers. It also demonstrates attacking 360 Total Security by nulling out itsObRegisterCallbacksand notify callbacks.Key Details:
- Use Case: Elevate privileges
- Privileges Required: kernel
- Operating System: Windows 10
- Author: Guus Verbeek
- Created: 2023-06-05
AsrCDDrv.sys driver overview
mainAsrCDDrv.sys is a kernel driver from ASRock Incorporation used for privilege escalation. It provides several high-privilege capabilities including:
- Control register read/write (cr0, cr2, cr3, cr4, cr8)
- Arbitrary MSR read/write
- Arbitrary physical memory read/write via
MmMapIoSpace - Contiguous memory allocation/free via
MmAllocateContiguousMemorySpecifyCache - I/O port read/write (8/16/32-bit)
Metadata:
- UUID:
bd06e043-0f69-4212-be93-d069bf0de848 - Operating System: Windows 10
- Privileges: kernel
Information about the amp.sys vulnerable driver
mainamp.sys Overview
amp.sysis a vulnerable kernel driver used for privilege escalation on Windows 10.- UUID:
ca768fc5-9b5c-4ced-90ab-fd6be9a70199 - Created: 2023-01-09
- Author: Michael Haag
- Use Case: Elevate privileges
- Privileges: kernel
- Operating System: Windows 10
- Company: CYREN Inc.
- Product: CYREN AMP 5
- Description: AMP Minifilter
- UUID: