gmh5225/BYOVD
Some POCs for my BYOVD research and find some vulnerable drivers
Intercepting DeviceControl via WPP
Appears on
Quick read
Latest capture 2026-07-29 03:06
0 paths
Agent instructions and tool configuration found in this repository.
No config files detected.
3 observed captures since 2026-06-24. Charts use measured snapshots only.
Stars from first capture +1
All tracked data
Observed snapshots
Observed snapshots
Nearest indexed repositories by embedding similarity.
Some POCs for my BYOVD research and find some vulnerable drivers
Proof of Concepts code for Bring Your Own Vulnerable Driver techniques
PoC exploit for the vulnerable WatchDog Anti-Malware driver (amsdk.sys) – weaponized to kill protected EDR/AV processes via BYOVD.
CVE-2022-42046 Proof of Concept of wfshbr64.sys local privilege escalation via DKOM
A proof of concept demonstrating communication via mapped shared memory structures between a user-mode process and a kernel-mode payload on Windows 10 20H2.
Spoofing the Windows 10 HDD/diskdrive serialnumber from kernel without hooking