GhostDriver is a publicly available, open-source BYOVD AV/EDR killer used to terminate protected security processes on Windows systems. The content describes it as an unmodified build of the open-source GhostDriver project and a proof of concept created by BlackSnufkin; one source also notes dead-av was openly described by its author as a Go rewrite of GhostDriver. GhostDriver leverages vulnerable signed drivers to kill processes from kernel mode, specifically loading the vulnerable RentDrv2 driver and abusing CVE-2023-44976. It is repeatedly characterized as a tool that automates abuse of vulnerable drivers to terminate security software processes, and one mention describes it as using truesight.sys to terminate specified AV/EDR process names. It appears in reporting on the broader BYOVD ecosystem alongside tools such as TrueSightKiller, AuKill, Poortry, Gmer, and Warp AVKiller.
In observed intrusions linked with medium confidence to interconnected pro-Ukrainian hacktivist groups including 4BID, Hakerskii Kit, C.A.S., and Goffee, attackers used GhostDriver.exe from GitHub to kill protected security processes after initial access, which was often obtained via ProxyShell exploitation of Microsoft Exchange and deployment of the fd.aspx web shell. In that reporting, GhostDriver was used as part of post-compromise defense evasion prior to or alongside broader post-exploitation activity and ransomware deployment. The targeted security processes included products and components associated with Microsoft Defender, Kaspersky, Bitdefender, Avast, AVG, McAfee, Elastic, Sysmon, Wazuh, and IPBan. More generally, the content places GhostDriver among commonly used BYOVD tools seen in ransomware and EDR-killer operations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
GhostDriver.sys is hardcoded inside the GhostDriver executable and is a binary driver known as RentDrv2 (BadRentdrv2). It contains the CVE-2023-44976 vulnerability, which allows it to accept user-mode commands via DeviceIoControl, perform operations on processes from kernel mode, and bypass security mechanisms, including Protected Process. | Another utility used to kill security software processes is ghostdriver.exe, an unmodified build of the open-source project GhostDriver.
8 distinct techniques documented for this family, organized by ATT&CK tactic.
By leveraging a vulnerable driver, attackers can execute malicious actions in kernel mode. For example, after gaining administrative access, an attacker can install a signed but flawed driver and send it crafted commands to exploit its weaknesses. | Attackers are increasingly abusing trusted Windows drivers to turn off antivirus (AV) and endpoint detection and response (EDR) tools, using a technique known as Bring Your Own Vulnerable Driver (BYOVD).
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A BYOVD-enabled tool that automates abuse of legitimate vulnerable Windows drivers to disable or kill security products such as AV and EDR.
Open-source BYOVD utility used to terminate security processes. It drops and loads the vulnerable RentDrv2 driver, communicates with it via DeviceIoControl, repeatedly kills target processes at kernel level, and attempts to remove the driver and related artifacts afterward.
Open-source BYOVD utility used to terminate security processes by dropping and loading the vulnerable RentDrv2 driver and issuing kernel-mode termination commands in a loop.
truesight.sysを利用するRust製BYOVD AV/EDR Killerで、指定したセキュリティプロセスを終了させる。
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.