Living Off The Land Drivers

Know the driver.
Understand the risk.

Explore vulnerable and malicious Windows drivers. Find the hashes, examine the evidence, and put detections to work.

Recently added

ampg.sys

Nextron Systems identifies this exact sample as a rootkit combining network interception, obfuscated file operations, and security-product targeting. Observed and embedded…

Driver entries
687
Vulnerable & malicious drivers
Known samples
2,390
Across all catalog entries
Load despite HVCI
479
Samples with a recorded TRUE result
HVCI status unknown
245
Samples without a recorded result

Driver explorer / THE CATALOG

687 driver entries
Driver / publisherClassificationHVCI TRUESamplesAdded
ampg.sys →Microsoft CorporationMaliciousUnknown12026-09-08
MemLoaderCustomize.sys →Publisher not recordedMaliciousUnknown22026-09-08
PlugPlayService.sys →Publisher not recordedMaliciousUnknown22026-09-08
rksafe.sys →Publisher not recordedMaliciousUnknown12026-09-08
RzDev_00X10.sys →Publisher not recordedMaliciousUnknown12026-09-08
AsusSAIO.sys →ASUSTeK COMPUTER INC.VulnerableUnknown322026-08-31
atidsmxx.sys →Advanced Micro Devices, Inc.Vulnerable0 / 1 samples12026-08-31
BSMEM64_W10.sys →BIOSTAR GroupVulnerable0 / 1 samples12026-08-31
fbiosdrv.sys →FUJITSU CLIENT COMPUTING LIMITEDVulnerableUnknown92026-08-31
fekern.sys →FireEye, Inc.VulnerableUnknown22026-08-31
hax.sys →Intel CorporationVulnerableUnknown92026-08-31
PGPwded.sys →CA, Inc., a Broadcom subsidiaryVulnerableUnknown72026-08-31

Put the intelligence to work.

From a driver finding to your existing security workflow.