Audio.sys - Suspicious (58/100) - DriverShield Analysis

Analysis of Audio.sys: suspicious verdict, risk score 58/100. 2 YARA matches, 0/75 multi-engine detections. SHA256 8d19f51c8dedfac0. Kernel imports, IOCTL codes, MITRE ATT&CK, and code-signing details.

Audio.sys - Analysis Report

DriverShield analyzed the Windows kernel driver Audio.sys and assigned a verdict of Suspicious with a composite risk score of 58/100, indicating some risk signals warranting review (30-59 band).

VerdictSuspicious (58/100)
YARA matches2
Multi-engine detections0 / 75
File size138944 bytes
Code-signing signerGlobalSign Root CA
Analyzed2026-10-10
SHA2568d19f51c8dedfac0009d5f0a9af09e6fa4eceb71418e1a3d07a76223db1d7a64
SHA1906fc8aa7f9125750a17a065281ef50eefedd120
MD58f1c369b678150aa8a298ea6f283cd04

Driver identity

Version resource data embedded in the Audio.sys PE header, as extracted by the analysis engine.

File descriptionMicrosoft Virtual Audio Tablet Sample Driver
ProductWindows (R) Win 7 DDK driver
CompanyWindows (R) Win 7 DDK provider
Original filenameAudio.sys
Internal nameAudio.sys
File version10.0.10011.16384
CopyrightCopyright (C) Microsoft Corp.2013

How the 58/100 score breaks down

Each component is scored 0-100 and then weighted into the composite. See the analysis methodology for the exact formula.

ComponentSub-score
Multi-engine consensus0 / 100
YARA signature matches80 / 100
Dangerous kernel imports100 / 100
IOCTL dispatch surface84 / 100
Known-vulnerable corpus0 / 100
Code-signing state0 / 100
Packing and entropy0 / 100
Dynamic behaviour0 / 100
CVE cross-reference0 / 100

Kernel imports (24)

Kernel-mode APIs resolved from the Import Address Table of Audio.sys, ranked by exploitation relevance.

APIRiskWhy it matters
MmMapIoSpacecriticalHighly dangerous - potential for arbitrary code execution, memory corruption, or process termination
MmGetSystemRoutineAddresshighPotentially dangerous - could be used for privilege escalation or security bypass
ZwSetValueKeymediumModerate risk - system modification capability
ZwCreateKeymediumModerate risk - system modification capability
ObReferenceObjectByHandlemediumModerate risk - system modification capability
ZwWriteFilemediumModerate risk - system modification capability
MmUnmapIoSpacemediumModerate risk - system modification capability
IoCreateSymbolicLinklowStandard kernel API - generally benign
ZwCreateFilelowStandard kernel API - generally benign
KeInitializeEventlowStandard kernel API - generally benign
RtlInitUnicodeStringlowStandard kernel API - generally benign
KeDelayExecutionThreadlowStandard kernel API - generally benign
ZwOpenFilelowStandard kernel API - generally benign
ExAllocatePoolWithTaglowStandard kernel API - generally benign
KeWaitForSingleObjectlowStandard kernel API - generally benign
IoDeleteSymbolicLinklowStandard kernel API - generally benign
IofCompleteRequestlowStandard kernel API - generally benign
ZwCloselowStandard kernel API - generally benign
ExFreePoollowStandard kernel API - generally benign
KeSetEventlowStandard kernel API - generally benign
ZwOpenKeylowStandard kernel API - generally benign
IoCreateDevicelowStandard kernel API - generally benign
IoDeleteDevicelowStandard kernel API - generally benign
DbgPrintExlowStandard kernel API - generally benign

IOCTL dispatch codes (28)

Control codes reachable through the driver dispatch routine. Codes tied to published exploit code are flagged, since they are the primary Bring Your Own Vulnerable Driver (BYOVD) entry points.

CodeSeverityTransferDescription
0x0080958BhighMETHOD_NEITHERFILE_DEVICE_CUSTOM Function #1378
0x00808E8BhighMETHOD_NEITHERFILE_DEVICE_CUSTOM Function #930
0x0080838BhighMETHOD_NEITHERFILE_DEVICE_CUSTOM Function #226
0x0080A383highMETHOD_NEITHERFILE_DEVICE_CUSTOM Function #2272
0x00808B8BhighMETHOD_NEITHERFILE_DEVICE_CUSTOM Function #738
0x0080BB83highMETHOD_NEITHERFILE_DEVICE_CUSTOM Function #3808
0x00808F8BhighMETHOD_NEITHERFILE_DEVICE_CUSTOM Function #994
0x0080BE83highMETHOD_NEITHERFILE_DEVICE_CUSTOM Function #4000
0x002200F0mediumMETHOD_BUFFEREDFILE_DEVICE_UNKNOWN Function #60
0x00223004mediumMETHOD_BUFFEREDFILE_DEVICE_UNKNOWN Function #3073
0x00800014mediumMETHOD_BUFFEREDFILE_DEVICE_CUSTOM Function #5
0x00802484mediumMETHOD_BUFFEREDFILE_DEVICE_CUSTOM Function #2337
0x0022EFE8mediumMETHOD_BUFFEREDFILE_DEVICE_UNKNOWN Function #3066
0x00808B89mediumMETHOD_IN_DIRECTFILE_DEVICE_CUSTOM Function #738
0x008000F8mediumMETHOD_BUFFEREDFILE_DEVICE_CUSTOM Function #62
0x0080818DmediumMETHOD_IN_DIRECTFILE_DEVICE_CUSTOM Function #99
0x00807F0DmediumMETHOD_IN_DIRECTFILE_DEVICE_CUSTOM Function #4035
0x0080249CmediumMETHOD_BUFFEREDFILE_DEVICE_CUSTOM Function #2343
0x0034B30DmediumMETHOD_IN_DIRECTFILE_DEVICE_DISK Function #3267
0x0034DB0DmediumMETHOD_IN_DIRECTFILE_DEVICE_DISK Function #1731
0x00227B0DmediumMETHOD_IN_DIRECTFILE_DEVICE_UNKNOWN Function #3779
0x0080B789mediumMETHOD_IN_DIRECTFILE_DEVICE_CUSTOM Function #3554
0x00220074mediumMETHOD_BUFFEREDFILE_DEVICE_UNKNOWN Function #29
0x00340380mediumMETHOD_BUFFEREDFILE_DEVICE_DISK Function #224

Showing 24 of 28 extracted control codes.

PE sections

Section layout and Shannon entropy. High entropy in a code section is a packing or encryption indicator.

SectionVirtual sizeRaw sizeEntropyFlags
.text0x126B50x128006.38CODE, EXEC, READ
.rdata0x25540x26005.01IDATA, READ
.data0x53080x46003.24IDATA, READ, WRITE
.pdata0x0CA80x0E004.49IDATA, READ
INIT0x0C4C0x0E005.25CODE, EXEC, READ, DISCARD
.rsrc0x04680x06002.84IDATA, READ, DISCARD
.reloc0x04E40x06004.91IDATA, READ, DISCARD

Exploit mitigations

Control Flow GuardEnabled
ASLREnabled
DEPEnabled
Integrity checkNot enforced
Mitigation score100 / 100

YARA rule matches (2)

RuleSeverityDetects
BYOVD_MemRWcriticalPhys memory mapping + device creation
SUSP_PhysMemhighPhysical memory mapping

MITRE ATT&CK techniques (11)

Techniques this driver could enable if loaded by an adversary.

IDTechniqueTactic
T1003OS Credential DumpingCredential Access
T1003.001OS Credential Dumping: LSASS MemoryCredential Access
T1006Direct Volume AccessDefense Evasion
T1055.012Process HollowingDefense Evasion
T1068Exploitation for Privilege EscalationPrivilege Escalation
T1071Application Layer ProtocolCommand and Control
T1211Exploitation for Defense EvasionDefense Evasion
T1543.003Windows ServicePersistence
T1553.002Subvert Trust Controls: Code SigningDefense Evasion
T1569.002Service ExecutionExecution
T1652Device Driver DiscoveryDiscovery

Code-signing chain

SignerGlobalSign Root CA
Signer organisationGlobalSign nv-sa
IssuerGlobalSign Root CA
Serial40000000001154B5AC394
Valid from1998-09-01 12:00 UTC
Valid until2028-01-28 12:00 UTC
Signature validityVerified

Symbolic execution

Engine angr, status static_approximation, 0 paths explored at a maximum depth of 0. Vulnerability classes reached: 0. Exploitable paths: 0.

Frequently asked questions about Audio.sys

Is Audio.sys safe?

Based on DriverShield static and dynamic analysis, Audio.sys shows some suspicious signals and warrants manual review. Its composite risk score is 58/100 (verdict: suspicious). Always validate findings independently before acting.

What is the risk score of Audio.sys?

Audio.sys has a DriverShield composite risk score of 58/100, placing it in the suspicious verdict band. SHA256: 8d19f51c8dedfac0009d5f0a9af09e6fa4eceb71418e1a3d07a76223db1d7a64.

What is Audio.sys?

Audio.sys is a Windows kernel-mode driver (.sys) analyzed by DriverShield for vulnerabilities, BYOVD abuse potential, and malware indicators. It is code-signed by GlobalSign Root CA.

Related: Other drivers signed by GlobalSign Root CA · What an IOCTL dispatch code is · How YARA matching feeds the score · BYOVD research index · full driver database · CVE library · code signing atlas


DriverShield © 2025-2026 · Terms · Privacy · Contact