EasyAntiCheat_EOS.sys - Clean (16/100) - DriverShield Analysis

Analysis of EasyAntiCheat_EOS.sys: clean verdict, risk score 16/100. 0 YARA matches, 0/75 multi-engine detections. SHA256 a423d526f8c680de. Kernel imports, IOCTL codes, MITRE ATT&CK, and code-signing details.

EasyAntiCheat_EOS.sys - Analysis Report

DriverShield analyzed the Windows kernel driver EasyAntiCheat_EOS.sys and assigned a verdict of Clean with a composite risk score of 16/100, indicating no notable risk signals (0-29 band).

VerdictClean (16/100)
YARA matches0
Multi-engine detections0 / 75
File size39142928 bytes
Code-signing signerGlobalSign Code Signing Root R45
Analyzed2026-10-05
SHA256a423d526f8c680de7d117719b3479ddd47f9d57dd46ba5b0da284e066422d61f
SHA1e554bd586b03168d801eee373ca5a2304bda1ab4
MD51a9e817e49c0039be4ca96495394b22b

Driver identity

Version resource data embedded in the EasyAntiCheat_EOS.sys PE header, as extracted by the analysis engine.

File descriptionEasy Anti-Cheat (EOS) driver
ProductEasy Anti-Cheat (EOS)
CompanyEasyAntiCheat Oy
Internal nameEasyAntiCheat_EOS.sys
CopyrightCopyright Epic Games, Inc. All Rights Reserved.

How the 16/100 score breaks down

Each component is scored 0-100 and then weighted into the composite. See the analysis methodology for the exact formula.

ComponentSub-score
Multi-engine consensus0 / 100
YARA signature matches0 / 100
Dangerous kernel imports0 / 100
IOCTL dispatch surface100 / 100
Known-vulnerable corpus0 / 100
Code-signing state0 / 100
Packing and entropy80 / 100
Dynamic behaviour0 / 100
CVE cross-reference0 / 100

IOCTL dispatch codes (40)

Control codes reachable through the driver dispatch routine. Codes tied to published exploit code are flagged, since they are the primary Bring Your Own Vulnerable Driver (BYOVD) entry points.

CodeSeverityTransferDescription
0x008081B7highMETHOD_NEITHERFILE_DEVICE_CUSTOM Function #109
0x0034850FhighMETHOD_NEITHERFILE_DEVICE_DISK Function #323
0x0080BFF7highMETHOD_NEITHERFILE_DEVICE_CUSTOM Function #4093
0x0080858BhighMETHOD_NEITHERFILE_DEVICE_CUSTOM Function #354
0x008000BBhighMETHOD_NEITHERFILE_DEVICE_CUSTOM Function #46
0x0080840FhighMETHOD_NEITHERFILE_DEVICE_CUSTOM Function #259
0x002200C7highMETHOD_NEITHERFILE_DEVICE_UNKNOWN Function #49
0x0022B8FFhighMETHOD_NEITHERFILE_DEVICE_UNKNOWN Function #3647
0x00808F8BhighMETHOD_NEITHERFILE_DEVICE_CUSTOM Function #994
0x003406C7highMETHOD_NEITHERFILE_DEVICE_DISK Function #433
0x0080968BhighMETHOD_NEITHERFILE_DEVICE_CUSTOM Function #1442
0x008083C7highMETHOD_NEITHERFILE_DEVICE_CUSTOM Function #241
0x0080850FhighMETHOD_NEITHERFILE_DEVICE_CUSTOM Function #323
0x00800083highMETHOD_NEITHERFILE_DEVICE_CUSTOM Function #32
0x0080888BhighMETHOD_NEITHERFILE_DEVICE_CUSTOM Function #546
0x00809D8BhighMETHOD_NEITHERFILE_DEVICE_CUSTOM Function #1890
0x0080AD3BhighMETHOD_NEITHERFILE_DEVICE_CUSTOM Function #2894
0x00807D83highMETHOD_NEITHERFILE_DEVICE_CUSTOM Function #3936
0x0080830FhighMETHOD_NEITHERFILE_DEVICE_CUSTOM Function #195
0x008002C7highMETHOD_NEITHERFILE_DEVICE_CUSTOM Function #177
0x00800007highMETHOD_NEITHERFILE_DEVICE_CUSTOM Function #1
0x0080000BhighMETHOD_NEITHERFILE_DEVICE_CUSTOM Function #2
0x0080000FhighMETHOD_NEITHERFILE_DEVICE_CUSTOM Function #3
0x00800013highMETHOD_NEITHERFILE_DEVICE_CUSTOM Function #4

Showing 24 of 40 extracted control codes.

PE sections

Section layout and Shannon entropy. High entropy in a code section is a packing or encryption indicator.

SectionVirtual sizeRaw sizeEntropyFlags
.text0x17D2420x17D4004CODE, EXEC, READ
.rdata0x8DFB80x8E0005.59IDATA, READ
.data0x7618D0xB6006.77IDATA, READ, WRITE
0x64380x66000IDATA, READ
.rsrc0x03300x04002.75IDATA, READ, DISCARD
.reloc0x09900x0A005.29IDATA, READ, DISCARD
0x28000x28006.33CODE, EXEC, READ
0x23230000x23228006.53EXEC, READ
.pdata0xC0000xBC006.44READ

Exploit mitigations

Control Flow GuardNot enabled
ASLREnabled
DEPEnabled
Integrity checkEnforced
Mitigation score75 / 100

MITRE ATT&CK techniques (3)

Techniques this driver could enable if loaded by an adversary.

IDTechniqueTactic
T1071Application Layer ProtocolCommand and Control
T1543.003Windows ServicePersistence
T1652Device Driver DiscoveryDiscovery

Code-signing chain

SignerGlobalSign Code Signing Root R45
Signer organisationGlobalSign nv-sa
IssuerGlobalSign
Serial7803184245708A41CF6F01B8EEB4A954
Valid from2020-07-28 00:00 UTC
Valid until2029-03-18 00:00 UTC
Signature validityVerified

Symbolic execution

Engine angr, status static_approximation, 0 paths explored at a maximum depth of 0. Vulnerability classes reached: 0. Exploitable paths: 0.

Frequently asked questions about EasyAntiCheat_EOS.sys

Is EasyAntiCheat_EOS.sys safe?

Based on DriverShield static and dynamic analysis, EasyAntiCheat_EOS.sys is assessed as clean, with no notable risk signals. Its composite risk score is 16/100 (verdict: clean). Always validate findings independently before acting.

What is the risk score of EasyAntiCheat_EOS.sys?

EasyAntiCheat_EOS.sys has a DriverShield composite risk score of 16/100, placing it in the clean verdict band. SHA256: a423d526f8c680de7d117719b3479ddd47f9d57dd46ba5b0da284e066422d61f.

What is EasyAntiCheat_EOS.sys?

EasyAntiCheat_EOS.sys is a Windows kernel-mode driver (.sys) analyzed by DriverShield for vulnerabilities, BYOVD abuse potential, and malware indicators. It is code-signed by GlobalSign Code Signing Root R45.

Related: Other drivers signed by GlobalSign Code Signing Root R45 · What an IOCTL dispatch code is · BYOVD research index · full driver database · CVE library · code signing atlas


DriverShield © 2025-2026 · Terms · Privacy · Contact