BYOVD to the next level (part 2) — rootkit like it's 2025
blog.quarkslab.com | research | #windows | #post-exploitation | #kernel | #driver | #byovd | #reflective-loading
Summary
Part two of Quarkslab's BYOVD series: using read/write primitives from a vulnerable driver to reflectively load an unsigned driver from memory and bypass Windows Driver Signature Enforcement.
- Published
- Collected
Skip to content