Elastic Security Labs said Elastic Defend now detects more than 800 known vulnerable Windows drivers used in bring-your-own-vulnerable-driver (BYOVD) attacks, a technique that lets attackers load legitimately signed but flawed drivers to gain kernel-level access, tamper with memory, and disable security tools. The expanded coverage builds on an automated pipeline that monitors public sources including VirusTotal, LOLDrivers, and Microsoft’s Vulnerable Driver Block List to rapidly generate and ship new YARA-based detections; Elastic said its coverage started in 2023 with 65 rules and has since grown substantially.
The update comes as BYOVD remains a favored tactic in ransomware and intrusion campaigns, with Elastic and other researchers pointing to abuse of Avast’s signed anti-rootkit driver aswArPot.sys in Cuba ransomware activity and GHOSTENGINE operations. Elastic said the product also applies layered protections such as vulnerable-driver blocklist validation before driver load and alerts on first-seen drivers, while related platform updates add automated troubleshooting in Elastic Agent Builder and support for Windows on ARM in Elastic Defend.

See real exploitation activity before you spend the cycle.
5 events from the most recent confirmed update back to the earliest known activity.
Elastic states its automated process for generating vulnerable-driver detection rules began in 2023. The effort started with coverage for 65 vulnerable drivers.
Elastic Defend now supports Windows on ARM. Elastic says Snapdragon laptops, Copilot+ PCs, and ARM workstations can enroll under existing policies and report the same telemetry as x64 endpoints.
Elastic Agent Builder now includes automatic troubleshooting capabilities. Elastic says this covers issues such as third-party antivirus conflicts, policy application failures, and other troubleshooting errors.
Elastic publishes every generated vulnerable-driver rule publicly in its elastic/protections-artifacts repository. The repository shows which driver triggered a rule, which source flagged it, and the detection logic.
Elastic says its vulnerable-driver rule library now covers more than 800 known vulnerable drivers. The coverage is generated from monitored public disclosure sources and made recognizable by Elastic Defend without customer-side updates or settings changes.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
2 references tracked. Mallory keeps watching after this page renders.
helpnetsecurity.com
Open sourceelastic.co
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.