Fortinet disclosed two techniques that can let attackers load unsigned kernel drivers on Windows systems by tampering with Driver Signature Enforcement (DSE) at runtime, despite protections such as Code Integrity, PatchGuard, Virtualization-based Security, and Microsoft’s recommended vulnerable-driver block rules. The methods, dubbed Page Swapping and Callback Swapping, abuse kernel write access—often obtained through vulnerable third-party drivers—to redirect protected Code Integrity policy data or replace validation callbacks in ntoskrnl.exe, causing malicious drivers to be accepted as trusted.
The report says Microsoft’s Kernel Data Protection (KDP) and driver blocklists raise the bar but do not fully stop runtime DSE tampering when Hypervisor-protected Code Integrity (HVCI) is not enabled, because driver validation can still be manipulated in the normal kernel. The findings build on a long history of DSE bypass tradecraft, including Turla-linked tooling such as TDL, a loader that mapped specially crafted unsigned drivers into kernel memory without modifying standard Code Integrity variables, underscoring how kernel-level access and vulnerable drivers remain a practical path to stealthy persistence and defense evasion on Windows.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
Fortinet published research describing two new Driver Signature Enforcement tampering methods, "Page Swapping" and "Callback Swapping," for loading unsigned kernel drivers despite Microsoft protections. The post also explains why HVCI remains the strongest mitigation and outlines defender detection ideas.
Microsoft introduced Kernel Data Protection as a platform security technology to prevent kernel data corruption. The Fortinet analysis later cites it as a mitigation relevant to Driver Signature Enforcement tampering.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
fortinet.com
Open sourcemicrosoft.com
Open sourcegithub.com
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.