I've found an exploit in one of drivers of a windows software, which could be possibly used for BYOVD the Driver is signed and the certificate is valid.
Works from Win 7 - 11, both x64 & x86 are supported.
The IOCTL requests sent are unchecked.
There are certain exports one of them is ZwTerminateProcess to perform something like what terminator does.
EDR(Runtime) Results -
Scantime Results -
I can provide video proof upon request in PM.
The driver isn't public from loldriver, github etc...
Looking if someone is interested in buying the driver.
Works from Win 7 - 11, both x64 & x86 are supported.
The IOCTL requests sent are unchecked.
There are certain exports one of them is ZwTerminateProcess to perform something like what terminator does.
EDR(Runtime) Results -
I can provide video proof upon request in PM.
The driver isn't public from loldriver, github etc...
Looking if someone is interested in buying the driver.