Skip to main content

Live threat intelligence

LOLDrivers Database

Search, analyze, and hunt vulnerable and malicious Windows drivers used in real-world attacks.

Updated Loading…

Total drivers0Catalogued samples
MVDB passed0Click to filter
Process killers0Click to filter
Quick
Behaviors
Certificates
Architecture

Toggle filters, then Apply. Search runs live as you type.

Showing 20 of 2,314 drivers · page 1 of 116

PhantomKiller

x64

LENOVO · 2018-01-03

MVDB PASSED
FEATURED KILLER
PROCESS KILLER

DescriptionPhantomKiller is the newly released, featured process-killer variant based on Lenovo BootRepair.sys. It is tracked separately from the base BootRepair entry: the project ships it as PhantomKiller.sys, while the underlying vulnerable driver lineage is BootRepair.sys from Lenovo PC Manager. The driver exposes \\.\BootRepair without secure DACL restrictions and accepts IOCTL 0x222014 with a 4-byte PID, then calls PsLookupProcessByProcessId, ObOpenObjectByPointer, and ZwTerminateProcess to terminate protected EDR/AV processes.

Process Killer

Operating System

Windows x64

Privileges

Driver load requires administrative privileges; an already loaded driver can be abused by a low-privileged user according to the project README.

Use Case

BYOVD process termination against EDR/AV protected processes.

Command

Terminal
sc.exe create PhantomKiller binPath="C:\Path\to\PhantomKiller.sys" type=kernel
sc.exe start PhantomKiller
PhantomKiller.exe <pid>
github.com/redteamfortress/PhantomKillergithub.com/redteamfortress/PhantomKiller/releases/tag/v1.0.0github.com/redteamfortress/PhantomKiller/releases/downloa...github.com/redteamfortress/PhantomKiller/raw/refs/heads/m...medium.com/@jehadbudagga/phantom-killer-reverse-engineeri...

echo_driver.sys

x64

2023-07-14

MVDB BLOCKED
VALID CERTIFICATE
VALID CERTIFICATE

DescriptionBad access controls in Inspect Element Ltd.'s echo_driver.sys allows attacker to gain arbitrary memory read and write, which allows for easy Privilege Escalation via Token Theft.

Memory Manipulator
Debug Bypass
File Manipulator

Operating System

Windows 10/11

Privileges

kernel

Use Case

Elevate privileges, arbitrary memory read/write

Command

Terminal
sc.exe create echo_driver.sys binPath=C:\windows\temp\echo_driver.sys type=kernel && sc.exe start echo_driver.sys
ioctl.fail/echo-ac-writeup/github.com/kite03/echoac-poc/tree/main/PoCgithub.com/pseuxide/kur

echodriver

2023-07-14

MVDB BLOCKED
PROCESS KILLER
VALID CERTIFICATE
VALID CERTIFICATE

DescriptionBad access controls in Inspect Element Ltd.'s echo_driver.sys allows attacker to gain arbitrary memory read and write, which allows for easy Privilege Escalation via Token Theft.

Process Killer
File Manipulator

Operating System

Windows 10/11

Privileges

kernel

Use Case

Elevate privileges, arbitrary memory read/write

Command

Terminal
sc.exe create echo_driver.sys binPath=C:\windows\temp\echo_driver.sys type=kernel && sc.exe start echo_driver.sys
ioctl.fail/echo-ac-writeup/github.com/kite03/echoac-poc/tree/main/PoCgithub.com/pseuxide/kur

echodriver.sys

2023-07-14

MVDB BLOCKED
VALID CERTIFICATE
VALID CERTIFICATE

DescriptionBad access controls in Inspect Element Ltd.'s echo_driver.sys allows attacker to gain arbitrary memory read and write, which allows for easy Privilege Escalation via Token Theft.

Memory Manipulator
Debug Bypass
Registry Manipulator
File Manipulator

Operating System

Windows 10/11

Privileges

kernel

Use Case

Elevate privileges, arbitrary memory read/write

Command

Terminal
sc.exe create echo_driver.sys binPath=C:\windows\temp\echo_driver.sys type=kernel && sc.exe start echo_driver.sys
ioctl.fail/echo-ac-writeup/github.com/kite03/echoac-poc/tree/main/PoCgithub.com/pseuxide/kur

echo.sys

x32

2023-07-14

MVDB BLOCKED
PROCESS KILLER
EXPIRED CERTIFICATE
EXPIRED CERTIFICATE

DescriptionBad access controls in Inspect Element Ltd.'s echo_driver.sys allows attacker to gain arbitrary memory read and write, which allows for easy Privilege Escalation via Token Theft.

Process Killer
Memory Manipulator
File Manipulator

Operating System

Windows 10/11

Privileges

kernel

Use Case

Elevate privileges, arbitrary memory read/write

Command

Terminal
sc.exe create echo_driver.sys binPath=C:\windows\temp\echo_driver.sys type=kernel && sc.exe start echo_driver.sys
ioctl.fail/echo-ac-writeup/github.com/kite03/echoac-poc/tree/main/PoCgithub.com/pseuxide/kur

rentdrv2.sys

x64

2023-07-14

MVDB BLOCKED
PROCESS KILLER
VALID CERTIFICATE
VALID CERTIFICATE

DescriptionBad access controls in Inspect Element Ltd.'s echo_driver.sys allows attacker to gain arbitrary memory read and write, which allows for easy Privilege Escalation via Token Theft.

Process Killer
Memory Manipulator
Debug Bypass
File Manipulator

Operating System

Windows 10/11

Privileges

kernel

Use Case

Elevate privileges, arbitrary memory read/write

Command

Terminal
sc.exe create echo_driver.sys binPath=C:\windows\temp\echo_driver.sys type=kernel && sc.exe start echo_driver.sys
ioctl.fail/echo-ac-writeup/github.com/kite03/echoac-poc/tree/main/PoCgithub.com/pseuxide/kur

NodeDriver.sys

x64

2023-03-02

MVDB BLOCKED
VALID CERTIFICATE
VALID CERTIFICATE

DescriptionDriver categorized as POORTRY by Mandiant.

Memory Manipulator

Operating System

Windows 10

Privileges

kernel

Use Case

Elevate privileges

Command

Terminal
sc.exe create NodeDriver.sys binPath=C:\windows\temp\NodeDriver.sys type=kernel && sc.exe start NodeDriver.sys
www.mandiant.com/resources/blog/hunting-attestation-signe...

ElbyCDIO.sys

x32

Elaborate Bytes AG · 2023-01-09

MVDB BLOCKED
EXPIRED CERTIFICATE
EXPIRED CERTIFICATE

Descriptionelbycdio.sys is a vulnerable driver. CVE-2009-0824.

Memory Manipulator
Debug Bypass
File Manipulator

Operating System

Windows 10

Privileges

kernel

Use Case

Elevate privileges

Command

Terminal
sc.exe create elbycdio.sys binPath=C:\windows\temp\elbycdio.sys type=kernel && sc.exe start elbycdio.sys
github.com/jbaines-r7/delliciouswww.rapid7.com/blog/post/2021/12/13/driver-based-attacks-...media.kasperskycontenthub.com/wp-content/uploads/sites/43...

ElbyCDIO.sys

x64

Elaborate Bytes AG · 2023-01-09

MVDB BLOCKED
EXPIRED CERTIFICATE
EXPIRED CERTIFICATE

Descriptionelbycdio.sys is a vulnerable driver. CVE-2009-0824.

Memory Manipulator
Debug Bypass
File Manipulator

Operating System

Windows 10

Privileges

kernel

Use Case

Elevate privileges

Command

Terminal
sc.exe create elbycdio.sys binPath=C:\windows\temp\elbycdio.sys type=kernel && sc.exe start elbycdio.sys
github.com/jbaines-r7/delliciouswww.rapid7.com/blog/post/2021/12/13/driver-based-attacks-...media.kasperskycontenthub.com/wp-content/uploads/sites/43...

ElbyCDIO.sys

x32

Elaborate Bytes AG · 2023-01-09

MVDB BLOCKED
EXPIRED CERTIFICATE
EXPIRED CERTIFICATE

Descriptionelbycdio.sys is a vulnerable driver. CVE-2009-0824.

Memory Manipulator
Registry Manipulator
File Manipulator

Operating System

Windows 10

Privileges

kernel

Use Case

Elevate privileges

Command

Terminal
sc.exe create elbycdio.sys binPath=C:\windows\temp\elbycdio.sys type=kernel && sc.exe start elbycdio.sys
github.com/jbaines-r7/delliciouswww.rapid7.com/blog/post/2021/12/13/driver-based-attacks-...media.kasperskycontenthub.com/wp-content/uploads/sites/43...

ElbyCDIO.sys

x32

Elaborate Bytes AG · 2023-01-09

MVDB BLOCKED
EXPIRED CERTIFICATE
EXPIRED CERTIFICATE

Descriptionelbycdio.sys is a vulnerable driver. CVE-2009-0824.

Memory Manipulator
Debug Bypass
Registry Manipulator
File Manipulator

Operating System

Windows 10

Privileges

kernel

Use Case

Elevate privileges

Command

Terminal
sc.exe create elbycdio.sys binPath=C:\windows\temp\elbycdio.sys type=kernel && sc.exe start elbycdio.sys
github.com/jbaines-r7/delliciouswww.rapid7.com/blog/post/2021/12/13/driver-based-attacks-...media.kasperskycontenthub.com/wp-content/uploads/sites/43...

ElbyCDIO.sys

x32

Elaborate Bytes AG · 2023-01-09

MVDB BLOCKED
EXPIRED CERTIFICATE
EXPIRED CERTIFICATE

Descriptionelbycdio.sys is a vulnerable driver. CVE-2009-0824.

Memory Manipulator
Debug Bypass
Registry Manipulator
File Manipulator

Operating System

Windows 10

Privileges

kernel

Use Case

Elevate privileges

Command

Terminal
sc.exe create elbycdio.sys binPath=C:\windows\temp\elbycdio.sys type=kernel && sc.exe start elbycdio.sys
github.com/jbaines-r7/delliciouswww.rapid7.com/blog/post/2021/12/13/driver-based-attacks-...media.kasperskycontenthub.com/wp-content/uploads/sites/43...

ElbyCDIO.sys

x32

Elaborate Bytes AG · 2023-01-09

MVDB BLOCKED
EXPIRED CERTIFICATE
EXPIRED CERTIFICATE

Descriptionelbycdio.sys is a vulnerable driver. CVE-2009-0824.

Memory Manipulator
Debug Bypass
Registry Manipulator
File Manipulator

Operating System

Windows 10

Privileges

kernel

Use Case

Elevate privileges

Command

Terminal
sc.exe create elbycdio.sys binPath=C:\windows\temp\elbycdio.sys type=kernel && sc.exe start elbycdio.sys
github.com/jbaines-r7/delliciouswww.rapid7.com/blog/post/2021/12/13/driver-based-attacks-...media.kasperskycontenthub.com/wp-content/uploads/sites/43...

ElbyCDIO.sys

x32

Elaborate Bytes AG · 2023-01-09

MVDB BLOCKED
EXPIRED CERTIFICATE
EXPIRED CERTIFICATE

Descriptionelbycdio.sys is a vulnerable driver. CVE-2009-0824.

Memory Manipulator
Registry Manipulator
File Manipulator

Operating System

Windows 10

Privileges

kernel

Use Case

Elevate privileges

Command

Terminal
sc.exe create elbycdio.sys binPath=C:\windows\temp\elbycdio.sys type=kernel && sc.exe start elbycdio.sys
github.com/jbaines-r7/delliciouswww.rapid7.com/blog/post/2021/12/13/driver-based-attacks-...media.kasperskycontenthub.com/wp-content/uploads/sites/43...

ElbyCDIO.sys

x64

Elaborate Bytes AG · 2023-01-09

MVDB BLOCKED
EXPIRED CERTIFICATE
EXPIRED CERTIFICATE

Descriptionelbycdio.sys is a vulnerable driver. CVE-2009-0824.

Memory Manipulator
Debug Bypass
Registry Manipulator
File Manipulator

Operating System

Windows 10

Privileges

kernel

Use Case

Elevate privileges

Command

Terminal
sc.exe create elbycdio.sys binPath=C:\windows\temp\elbycdio.sys type=kernel && sc.exe start elbycdio.sys
github.com/jbaines-r7/delliciouswww.rapid7.com/blog/post/2021/12/13/driver-based-attacks-...media.kasperskycontenthub.com/wp-content/uploads/sites/43...

ElbyCDIO.sys

x32

Elaborate Bytes AG · 2023-01-09

MVDB BLOCKED
EXPIRED CERTIFICATE
EXPIRED CERTIFICATE

Descriptionelbycdio.sys is a vulnerable driver. CVE-2009-0824.

Memory Manipulator
Debug Bypass
Registry Manipulator
File Manipulator

Operating System

Windows 10

Privileges

kernel

Use Case

Elevate privileges

Command

Terminal
sc.exe create elbycdio.sys binPath=C:\windows\temp\elbycdio.sys type=kernel && sc.exe start elbycdio.sys
github.com/jbaines-r7/delliciouswww.rapid7.com/blog/post/2021/12/13/driver-based-attacks-...media.kasperskycontenthub.com/wp-content/uploads/sites/43...

ElbyCDIO.sys

x32

Elaborate Bytes AG · 2023-01-09

MVDB BLOCKED
EXPIRED CERTIFICATE
EXPIRED CERTIFICATE

Descriptionelbycdio.sys is a vulnerable driver. CVE-2009-0824.

Memory Manipulator
Registry Manipulator
File Manipulator

Operating System

Windows 10

Privileges

kernel

Use Case

Elevate privileges

Command

Terminal
sc.exe create elbycdio.sys binPath=C:\windows\temp\elbycdio.sys type=kernel && sc.exe start elbycdio.sys
github.com/jbaines-r7/delliciouswww.rapid7.com/blog/post/2021/12/13/driver-based-attacks-...media.kasperskycontenthub.com/wp-content/uploads/sites/43...

ElbyCDIO.sys

x32

Elaborate Bytes AG · 2023-01-09

MVDB BLOCKED
EXPIRED CERTIFICATE
EXPIRED CERTIFICATE

Descriptionelbycdio.sys is a vulnerable driver. CVE-2009-0824.

Memory Manipulator
Debug Bypass
Registry Manipulator
File Manipulator

Operating System

Windows 10

Privileges

kernel

Use Case

Elevate privileges

Command

Terminal
sc.exe create elbycdio.sys binPath=C:\windows\temp\elbycdio.sys type=kernel && sc.exe start elbycdio.sys
github.com/jbaines-r7/delliciouswww.rapid7.com/blog/post/2021/12/13/driver-based-attacks-...media.kasperskycontenthub.com/wp-content/uploads/sites/43...

ElbyCDIO.sys

x32

Elaborate Bytes AG · 2023-01-09

MVDB BLOCKED
EXPIRED CERTIFICATE
EXPIRED CERTIFICATE

Descriptionelbycdio.sys is a vulnerable driver. CVE-2009-0824.

Memory Manipulator
Debug Bypass
File Manipulator

Operating System

Windows 10

Privileges

kernel

Use Case

Elevate privileges

Command

Terminal
sc.exe create elbycdio.sys binPath=C:\windows\temp\elbycdio.sys type=kernel && sc.exe start elbycdio.sys
github.com/jbaines-r7/delliciouswww.rapid7.com/blog/post/2021/12/13/driver-based-attacks-...media.kasperskycontenthub.com/wp-content/uploads/sites/43...

ElbyCDIO.sys

x64

Elaborate Bytes AG · 2023-01-09

MVDB BLOCKED
EXPIRED CERTIFICATE
EXPIRED CERTIFICATE

Descriptionelbycdio.sys is a vulnerable driver. CVE-2009-0824.

Memory Manipulator
Debug Bypass
Registry Manipulator
File Manipulator

Operating System

Windows 10

Privileges

kernel

Use Case

Elevate privileges

Command

Terminal
sc.exe create elbycdio.sys binPath=C:\windows\temp\elbycdio.sys type=kernel && sc.exe start elbycdio.sys
github.com/jbaines-r7/delliciouswww.rapid7.com/blog/post/2021/12/13/driver-based-attacks-...media.kasperskycontenthub.com/wp-content/uploads/sites/43...
Page 1 of 116

Special Thanks

This database is based on the amazing work from the LOLDrivers.io project and its contributors.

Source & Contributors

Original project: magicsword-io/LOLDrivers

This project: didntchooseaname/loldrivers-database

Independent interface for educational and research purposes.