Live threat intelligence
LOLDrivers Database
Search, analyze, and hunt vulnerable and malicious Windows drivers used in real-world attacks.
Updated Loading…
Toggle filters, then Apply. Search runs live as you type.
PhantomKiller
x64LENOVO · 2018-01-03
DescriptionPhantomKiller is the newly released, featured process-killer variant based on Lenovo BootRepair.sys. It is tracked separately from the base BootRepair entry: the project ships it as PhantomKiller.sys, while the underlying vulnerable driver lineage is BootRepair.sys from Lenovo PC Manager. The driver exposes \\.\BootRepair without secure DACL restrictions and accepts IOCTL 0x222014 with a 4-byte PID, then calls PsLookupProcessByProcessId, ObOpenObjectByPointer, and ZwTerminateProcess to terminate protected EDR/AV processes.
Operating System
Windows x64
Privileges
Driver load requires administrative privileges; an already loaded driver can be abused by a low-privileged user according to the project README.
Use Case
BYOVD process termination against EDR/AV protected processes.
Command
sc.exe create PhantomKiller binPath="C:\Path\to\PhantomKiller.sys" type=kernel
sc.exe start PhantomKiller
PhantomKiller.exe <pid>RWTKrl.sys
x32Pinchins Technology Co.,Ltd. · 2024-09-10
DescriptionSophos, from time to time, has observed a threat actor deploy variants of Poortry on different machines within a single estate during an attack. These variants contain the same payload, but signed with a different certificate than the driver first seen used during the attack.
Operating System
Windows 10
Privileges
kernel
Use Case
Elevate privileges
Command
sc.exe create driver_c3d48ddd.sys binPath=C:\windows\temp\driver_c3d48ddd.sys type=kernel && sc.exe start driver_c3d48ddd.sysNetfilter.sys
x322023-07-22
DescriptionConfirmed vulnerable driver from Microsoft Block List
Operating System
Windows
Privileges
kernel
Use Case
Elevate privileges
Netfilter.sys
x322023-07-22
DescriptionConfirmed vulnerable driver from Microsoft Block List
Operating System
Windows
Privileges
kernel
Use Case
Elevate privileges
Netfilter.sys
x642023-07-22
DescriptionConfirmed vulnerable driver from Microsoft Block List
Operating System
Windows
Privileges
kernel
Use Case
Elevate privileges
Netfilter.sys
x322023-07-22
DescriptionConfirmed vulnerable driver from Microsoft Block List
Operating System
Windows
Privileges
kernel
Use Case
Elevate privileges
Netfilter.sys
x642023-07-22
DescriptionConfirmed vulnerable driver from Microsoft Block List
Operating System
Windows
Privileges
kernel
Use Case
Elevate privileges
Netfilter.sys
x642023-07-22
DescriptionConfirmed vulnerable driver from Microsoft Block List
Operating System
Windows
Privileges
kernel
Use Case
Elevate privileges
Netfilter.sys
x642023-07-22
DescriptionConfirmed vulnerable driver from Microsoft Block List
Operating System
Windows
Privileges
kernel
Use Case
Elevate privileges
Netfilter.sys
x642023-07-22
DescriptionConfirmed vulnerable driver from Microsoft Block List
Operating System
Windows
Privileges
kernel
Use Case
Elevate privileges
Netfilter.sys
x642023-07-22
DescriptionConfirmed vulnerable driver from Microsoft Block List
Operating System
Windows
Privileges
kernel
Use Case
Elevate privileges
Netfilter.sys
x322023-07-22
DescriptionConfirmed vulnerable driver from Microsoft Block List
Operating System
Windows
Privileges
kernel
Use Case
Elevate privileges
Netfilter.sys
x322023-07-22
DescriptionConfirmed vulnerable driver from Microsoft Block List
Operating System
Windows
Privileges
kernel
Use Case
Elevate privileges
Netfilter.sys
x642023-07-22
DescriptionConfirmed vulnerable driver from Microsoft Block List
Operating System
Windows
Privileges
kernel
Use Case
Elevate privileges
Netfilter.sys
x642023-07-22
DescriptionConfirmed vulnerable driver from Microsoft Block List
Operating System
Windows
Privileges
kernel
Use Case
Elevate privileges
Netfilter.sys
x642023-07-22
DescriptionConfirmed vulnerable driver from Microsoft Block List
Operating System
Windows
Privileges
kernel
Use Case
Elevate privileges
Netfilter.sys
x322023-07-22
DescriptionConfirmed vulnerable driver from Microsoft Block List
Operating System
Windows
Privileges
kernel
Use Case
Elevate privileges
Netfilter.sys
x322023-07-22
DescriptionConfirmed vulnerable driver from Microsoft Block List
Operating System
Windows
Privileges
kernel
Use Case
Elevate privileges
DirectIo.sys
x322023-01-09
Operating System
Windows 10
Privileges
kernel
Use Case
Elevate privileges
Command
sc.exe create DirectIo.sys binPath=C:\windows\temp\DirectIo.sys type=kernel && sc.exe start DirectIo.sysEneTechIo64.sys
x642023-01-09
Operating System
Windows 10
Privileges
kernel
Use Case
Elevate privileges
Command
sc.exe create EneTechIo64.sys binPath=C:\windows\temp\EneTechIo64.sys type=kernel && sc.exe start EneTechIo64.sys