In this talk, we will cover reverse engineering Windows kernel-mode drivers, identifying vulnerabilities, and performing BYOVD (Bring Your Own Vulnerable Driver) attacks. We will learn techniques to exploit driver vulnerabilities in order to bypass EDRs or gain kernel-level permissions. Additionally, we will review BYOVD attacks carried out by real APTs and how they disable EDRs and antivirus software using kernel-mode techniques.
Presented at BSides Las Vegas 2026