BYOVD attacks have helped ransomware crews and advanced actors disable security tools, hide activity, and move from admin control towards the kernel. Microsoft’s 2026 Windows Driver Policy is a major hardening step, but it does not make kernel-driver risk disappear. This talk explains what the new policy blocks, what it only audits, and what defenders still need to hunt. Using cases including BlackByte, POORTRY/STONESTOP, and Lazarus/FudModule, we will build a practical approach to driver inventory, Code Integrity events, audit-mode visibility, and reducing kernel attack surface.