Ghost in the Kernel: Hunting BYOVD After Microsoft’s 2026 Driver Trust Shift

No ratings

Presented at BSides Bristol 2026 by

BYOVD attacks have helped ransomware crews and advanced actors disable security tools, hide activity, and move from admin control towards the kernel. Microsoft’s 2026 Windows Driver Policy is a major hardening step, but it does not make kernel-driver risk disappear. This talk explains what the new policy blocks, what it only audits, and what defenders still need to hunt. Using cases including BlackByte, POORTRY/STONESTOP, and Lazarus/FudModule, we will build a practical approach to driver inventory, Code Integrity events, audit-mode visibility, and reducing kernel attack surface.