Live threat intelligence
LOLDrivers Database
Search, analyze, and hunt vulnerable and malicious Windows drivers used in real-world attacks.
Updated Loading…
Toggle filters, then Apply. Search runs live as you type.
PhantomKiller
x64LENOVO · 2018-01-03
DescriptionPhantomKiller is the newly released, featured process-killer variant based on Lenovo BootRepair.sys. It is tracked separately from the base BootRepair entry: the project ships it as PhantomKiller.sys, while the underlying vulnerable driver lineage is BootRepair.sys from Lenovo PC Manager. The driver exposes \\.\BootRepair without secure DACL restrictions and accepts IOCTL 0x222014 with a 4-byte PID, then calls PsLookupProcessByProcessId, ObOpenObjectByPointer, and ZwTerminateProcess to terminate protected EDR/AV processes.
Operating System
Windows x64
Privileges
Driver load requires administrative privileges; an already loaded driver can be abused by a low-privileged user according to the project README.
Use Case
BYOVD process termination against EDR/AV protected processes.
Command
sc.exe create PhantomKiller binPath="C:\Path\to\PhantomKiller.sys" type=kernel
sc.exe start PhantomKiller
PhantomKiller.exe <pid>echo_driver.sys
x642023-07-14
DescriptionBad access controls in Inspect Element Ltd.'s echo_driver.sys allows attacker to gain arbitrary memory read and write, which allows for easy Privilege Escalation via Token Theft.
Operating System
Windows 10/11
Privileges
kernel
Use Case
Elevate privileges, arbitrary memory read/write
Command
sc.exe create echo_driver.sys binPath=C:\windows\temp\echo_driver.sys type=kernel && sc.exe start echo_driver.sysechodriver
2023-07-14
DescriptionBad access controls in Inspect Element Ltd.'s echo_driver.sys allows attacker to gain arbitrary memory read and write, which allows for easy Privilege Escalation via Token Theft.
Operating System
Windows 10/11
Privileges
kernel
Use Case
Elevate privileges, arbitrary memory read/write
Command
sc.exe create echo_driver.sys binPath=C:\windows\temp\echo_driver.sys type=kernel && sc.exe start echo_driver.sysechodriver.sys
2023-07-14
DescriptionBad access controls in Inspect Element Ltd.'s echo_driver.sys allows attacker to gain arbitrary memory read and write, which allows for easy Privilege Escalation via Token Theft.
Operating System
Windows 10/11
Privileges
kernel
Use Case
Elevate privileges, arbitrary memory read/write
Command
sc.exe create echo_driver.sys binPath=C:\windows\temp\echo_driver.sys type=kernel && sc.exe start echo_driver.sysecho.sys
x322023-07-14
DescriptionBad access controls in Inspect Element Ltd.'s echo_driver.sys allows attacker to gain arbitrary memory read and write, which allows for easy Privilege Escalation via Token Theft.
Operating System
Windows 10/11
Privileges
kernel
Use Case
Elevate privileges, arbitrary memory read/write
Command
sc.exe create echo_driver.sys binPath=C:\windows\temp\echo_driver.sys type=kernel && sc.exe start echo_driver.sysrentdrv2.sys
x642023-07-14
DescriptionBad access controls in Inspect Element Ltd.'s echo_driver.sys allows attacker to gain arbitrary memory read and write, which allows for easy Privilege Escalation via Token Theft.
Operating System
Windows 10/11
Privileges
kernel
Use Case
Elevate privileges, arbitrary memory read/write
Command
sc.exe create echo_driver.sys binPath=C:\windows\temp\echo_driver.sys type=kernel && sc.exe start echo_driver.sysNodeDriver.sys
x642023-03-02
DescriptionDriver categorized as POORTRY by Mandiant.
Operating System
Windows 10
Privileges
kernel
Use Case
Elevate privileges
Command
sc.exe create NodeDriver.sys binPath=C:\windows\temp\NodeDriver.sys type=kernel && sc.exe start NodeDriver.sysElbyCDIO.sys
x32Elaborate Bytes AG · 2023-01-09
Descriptionelbycdio.sys is a vulnerable driver. CVE-2009-0824.
Operating System
Windows 10
Privileges
kernel
Use Case
Elevate privileges
Command
sc.exe create elbycdio.sys binPath=C:\windows\temp\elbycdio.sys type=kernel && sc.exe start elbycdio.sysElbyCDIO.sys
x64Elaborate Bytes AG · 2023-01-09
Descriptionelbycdio.sys is a vulnerable driver. CVE-2009-0824.
Operating System
Windows 10
Privileges
kernel
Use Case
Elevate privileges
Command
sc.exe create elbycdio.sys binPath=C:\windows\temp\elbycdio.sys type=kernel && sc.exe start elbycdio.sysElbyCDIO.sys
x32Elaborate Bytes AG · 2023-01-09
Descriptionelbycdio.sys is a vulnerable driver. CVE-2009-0824.
Operating System
Windows 10
Privileges
kernel
Use Case
Elevate privileges
Command
sc.exe create elbycdio.sys binPath=C:\windows\temp\elbycdio.sys type=kernel && sc.exe start elbycdio.sysElbyCDIO.sys
x32Elaborate Bytes AG · 2023-01-09
Descriptionelbycdio.sys is a vulnerable driver. CVE-2009-0824.
Operating System
Windows 10
Privileges
kernel
Use Case
Elevate privileges
Command
sc.exe create elbycdio.sys binPath=C:\windows\temp\elbycdio.sys type=kernel && sc.exe start elbycdio.sysElbyCDIO.sys
x32Elaborate Bytes AG · 2023-01-09
Descriptionelbycdio.sys is a vulnerable driver. CVE-2009-0824.
Operating System
Windows 10
Privileges
kernel
Use Case
Elevate privileges
Command
sc.exe create elbycdio.sys binPath=C:\windows\temp\elbycdio.sys type=kernel && sc.exe start elbycdio.sysElbyCDIO.sys
x32Elaborate Bytes AG · 2023-01-09
Descriptionelbycdio.sys is a vulnerable driver. CVE-2009-0824.
Operating System
Windows 10
Privileges
kernel
Use Case
Elevate privileges
Command
sc.exe create elbycdio.sys binPath=C:\windows\temp\elbycdio.sys type=kernel && sc.exe start elbycdio.sysElbyCDIO.sys
x32Elaborate Bytes AG · 2023-01-09
Descriptionelbycdio.sys is a vulnerable driver. CVE-2009-0824.
Operating System
Windows 10
Privileges
kernel
Use Case
Elevate privileges
Command
sc.exe create elbycdio.sys binPath=C:\windows\temp\elbycdio.sys type=kernel && sc.exe start elbycdio.sysElbyCDIO.sys
x64Elaborate Bytes AG · 2023-01-09
Descriptionelbycdio.sys is a vulnerable driver. CVE-2009-0824.
Operating System
Windows 10
Privileges
kernel
Use Case
Elevate privileges
Command
sc.exe create elbycdio.sys binPath=C:\windows\temp\elbycdio.sys type=kernel && sc.exe start elbycdio.sysElbyCDIO.sys
x32Elaborate Bytes AG · 2023-01-09
Descriptionelbycdio.sys is a vulnerable driver. CVE-2009-0824.
Operating System
Windows 10
Privileges
kernel
Use Case
Elevate privileges
Command
sc.exe create elbycdio.sys binPath=C:\windows\temp\elbycdio.sys type=kernel && sc.exe start elbycdio.sysElbyCDIO.sys
x32Elaborate Bytes AG · 2023-01-09
Descriptionelbycdio.sys is a vulnerable driver. CVE-2009-0824.
Operating System
Windows 10
Privileges
kernel
Use Case
Elevate privileges
Command
sc.exe create elbycdio.sys binPath=C:\windows\temp\elbycdio.sys type=kernel && sc.exe start elbycdio.sysElbyCDIO.sys
x32Elaborate Bytes AG · 2023-01-09
Descriptionelbycdio.sys is a vulnerable driver. CVE-2009-0824.
Operating System
Windows 10
Privileges
kernel
Use Case
Elevate privileges
Command
sc.exe create elbycdio.sys binPath=C:\windows\temp\elbycdio.sys type=kernel && sc.exe start elbycdio.sysElbyCDIO.sys
x32Elaborate Bytes AG · 2023-01-09
Descriptionelbycdio.sys is a vulnerable driver. CVE-2009-0824.
Operating System
Windows 10
Privileges
kernel
Use Case
Elevate privileges
Command
sc.exe create elbycdio.sys binPath=C:\windows\temp\elbycdio.sys type=kernel && sc.exe start elbycdio.sysElbyCDIO.sys
x64Elaborate Bytes AG · 2023-01-09
Descriptionelbycdio.sys is a vulnerable driver. CVE-2009-0824.
Operating System
Windows 10
Privileges
kernel
Use Case
Elevate privileges
Command
sc.exe create elbycdio.sys binPath=C:\windows\temp\elbycdio.sys type=kernel && sc.exe start elbycdio.sys