Analysis of appid.sys: suspicious verdict, risk score 58/100. 2 YARA matches, 0/76 multi-engine detections. SHA256 7031fec4cebddad6. Kernel imports, IOCTL codes, MITRE ATT&CK, and code-signing details.
DriverShield analyzed the Windows kernel driver appid.sys and assigned a verdict of Suspicious with a composite risk score of 58/100, indicating some risk signals warranting review (30-59 band).
| Verdict | Suspicious (58/100) |
| YARA matches | 2 |
| Multi-engine detections | 0 / 76 |
| File size | 208696 bytes |
| Code-signing signer | Microsoft Windows |
| Analyzed | 2026-09-06 |
| SHA256 | 7031fec4cebddad6e55df0da8d17c1c5eec92899a816130d1f68916bda39e03a |
| SHA1 | 719a0abe5f17040a69a604bde633397348c618ee |
| MD5 | 48a2317dce7698fada2420608ed15efe |
Version resource data embedded in the appid.sys PE header, as extracted by the analysis engine.
| File description | AppID Driver |
|---|---|
| Product | \VarFileInfo\Translation |
| Company | Microsoft Corporation |
| Original filename | appid.sys |
| Internal name | appid.sys |
| File version | 10.0.19041.488 (WinBuild.160101.0800) |
| Copyright | © Microsoft Corporation. All rights reserved. |
Each component is scored 0-100 and then weighted into the composite. See the analysis methodology for the exact formula.
| Component | Sub-score |
|---|---|
| Multi-engine consensus | 0 / 100 |
| YARA signature matches | 55 / 100 |
| Dangerous kernel imports | 100 / 100 |
| IOCTL dispatch surface | 100 / 100 |
| Known-vulnerable corpus | 0 / 100 |
| Code-signing state | 80 / 100 |
| Packing and entropy | 0 / 100 |
| Dynamic behaviour | 0 / 100 |
| CVE cross-reference | 0 / 100 |
Kernel-mode APIs resolved from the Import Address Table of appid.sys, ranked by exploitation relevance.
| API | Risk | Why it matters |
|---|---|---|
| MmGetSystemRoutineAddress | high | Potentially dangerous - could be used for privilege escalation or security bypass |
| PsSetCreateProcessNotifyRoutineEx | high | Potentially dangerous - could be used for privilege escalation or security bypass |
| PsLookupProcessByProcessId | high | Potentially dangerous - could be used for privilege escalation or security bypass |
| ZwOpenProcess | high | Potentially dangerous - could be used for privilege escalation or security bypass |
| ZwDeleteFile | medium | Moderate risk - system modification capability |
| ObReferenceObjectByHandle | medium | Moderate risk - system modification capability |
| KeBugCheckEx | medium | Moderate risk - system modification capability |
| ZwSetValueKey | medium | Moderate risk - system modification capability |
| ObOpenObjectByPointer | medium | Moderate risk - system modification capability |
| ZwWriteFile | medium | Moderate risk - system modification capability |
| ZwCreateKey | medium | Moderate risk - system modification capability |
| ZwQueryValueKey | low | Standard kernel API - generally benign |
| SeAccessCheck | low | Standard kernel API - generally benign |
| ZwQueryInformationFile | low | Standard kernel API - generally benign |
| IoCreateDevice | low | Standard kernel API - generally benign |
| ZwClose | low | Standard kernel API - generally benign |
| ZwOpenKey | low | Standard kernel API - generally benign |
| KeDelayExecutionThread | low | Standard kernel API - generally benign |
| IoCreateSymbolicLink | low | Standard kernel API - generally benign |
| IoDeleteDevice | low | Standard kernel API - generally benign |
| RtlInitAnsiString | low | Standard kernel API - generally benign |
| IoDeleteSymbolicLink | low | Standard kernel API - generally benign |
| KeWaitForSingleObject | low | Standard kernel API - generally benign |
| ZwCreateFile | low | Standard kernel API - generally benign |
| ZwReadFile | low | Standard kernel API - generally benign |
| KeInitializeEvent | low | Standard kernel API - generally benign |
| IofCompleteRequest | low | Standard kernel API - generally benign |
| RtlInitUnicodeString | low | Standard kernel API - generally benign |
Showing the 28 highest-relevance imports of 31 resolved.
Control codes reachable through the driver dispatch routine. Codes tied to published exploit code are flagged, since they are the primary Bring Your Own Vulnerable Driver (BYOVD) entry points.
| Code | Severity | Transfer | Description |
|---|---|---|---|
| 0x0080880F | high | METHOD_NEITHER | FILE_DEVICE_CUSTOM Function #515 |
| 0x00340063 | high | METHOD_NEITHER | FILE_DEVICE_DISK Function #24 |
| 0x00340033 | high | METHOD_NEITHER | FILE_DEVICE_DISK Function #12 |
| 0x0022007B | high | METHOD_NEITHER | FILE_DEVICE_UNKNOWN Function #30 |
| 0x00340037 | high | METHOD_NEITHER | FILE_DEVICE_DISK Function #13 |
| 0x00223417 | high | METHOD_NEITHER | FILE_DEVICE_UNKNOWN Function #3333 |
| 0x0080860F | high | METHOD_NEITHER | FILE_DEVICE_CUSTOM Function #387 |
| 0x008045C7 | high | METHOD_NEITHER | FILE_DEVICE_CUSTOM Function #369 |
| 0x00808F03 | high | METHOD_NEITHER | FILE_DEVICE_CUSTOM Function #960 |
| 0x00808F8B | high | METHOD_NEITHER | FILE_DEVICE_CUSTOM Function #994 |
| 0x0080840F | high | METHOD_NEITHER | FILE_DEVICE_CUSTOM Function #259 |
| 0x0022BB07 | high | METHOD_NEITHER | FILE_DEVICE_UNKNOWN Function #3777 |
| 0x0022E8CF | high | METHOD_NEITHER | FILE_DEVICE_UNKNOWN Function #2611 |
| 0x00806583 | high | METHOD_NEITHER | FILE_DEVICE_CUSTOM Function #2400 |
| 0x002200F0 | medium | METHOD_BUFFERED | FILE_DEVICE_UNKNOWN Function #60 |
| 0x0080EF0D | medium | METHOD_IN_DIRECT | FILE_DEVICE_CUSTOM Function #3011 |
| 0x00805715 | medium | METHOD_IN_DIRECT | FILE_DEVICE_CUSTOM Function #1477 |
| 0x00801715 | medium | METHOD_IN_DIRECT | FILE_DEVICE_CUSTOM Function #1477 |
| 0x00802494 | medium | METHOD_BUFFERED | FILE_DEVICE_CUSTOM Function #2341 |
| 0x00802484 | medium | METHOD_BUFFERED | FILE_DEVICE_CUSTOM Function #2337 |
| 0x0080248C | medium | METHOD_BUFFERED | FILE_DEVICE_CUSTOM Function #2339 |
| 0x00228348 | medium | METHOD_BUFFERED | FILE_DEVICE_UNKNOWN Function #210 |
| 0x00228330 | medium | METHOD_BUFFERED | FILE_DEVICE_UNKNOWN Function #204 |
| 0x00220020 | medium | METHOD_BUFFERED | FILE_DEVICE_UNKNOWN Function #8 |
Showing 24 of 40 extracted control codes.
Section layout and Shannon entropy. High entropy in a code section is a packing or encryption indicator.
| Section | Virtual size | Raw size | Entropy | Flags |
|---|---|---|---|---|
| .text | 0x533F | 0x5400 | 6.27 | CODE, EXEC, READ |
| .rdata | 0xE9C0 | 0xEA00 | 4.44 | IDATA, READ |
| .data | 0x08A8 | 0x0200 | 3.04 | IDATA, READ, WRITE |
| .pdata | 0x10C8 | 0x1200 | 5.15 | IDATA, READ |
| .idata | 0x20F4 | 0x2200 | 4.88 | IDATA, READ |
| PAGE | 0x16CE5 | 0x16E00 | 6.31 | CODE, EXEC, READ |
| INIT | 0x0D22 | 0x0E00 | 6.01 | CODE, EXEC, READ, DISCARD |
| GFIDS | 0x009C | 0x0200 | 1.8 | IDATA, READ, DISCARD |
| .rsrc | 0x03E0 | 0x0400 | 3.28 | IDATA, READ, DISCARD |
| .reloc | 0x123C | 0x1400 | 5.85 | IDATA, READ, DISCARD |
| Control Flow Guard | Enabled |
|---|---|
| ASLR | Enabled |
| DEP | Enabled |
| Integrity check | Enforced |
| Mitigation score | 90 / 100 |
| Rule | Severity | Detects |
|---|---|---|
| SUSP_Callbacks | medium | Kernel callback registration |
| MAL_DSEBypass | critical | DSE bypass attempt |
Techniques this driver could enable if loaded by an adversary.
| ID | Technique | Tactic |
|---|---|---|
| T1014 | Rootkit | Defense Evasion |
| T1055.001 | Process Injection: DLL Injection | Defense Evasion |
| T1071 | Application Layer Protocol | Command and Control |
| T1112 | Modify Registry | Defense Evasion |
| T1211 | Exploitation for Defense Evasion | Defense Evasion |
| T1489 | Service Stop | Impact |
| T1543.003 | Windows Service | Persistence |
| T1547.001 | Registry Run Keys | Persistence |
| T1553.002 | Subvert Trust Controls: Code Signing | Defense Evasion |
| T1562.001 | Impair Defenses: Disable/Modify Tools | Defense Evasion |
| T1562.006 | Indicator Blocking | Defense Evasion |
| T1564.001 | Hidden Files and Directories | Defense Evasion |
| T1569.002 | Service Execution | Execution |
| T1652 | Device Driver Discovery | Discovery |
| Signer | Microsoft Windows |
|---|---|
| Signer organisation | Microsoft Corporation |
| Issuer | Microsoft Windows Production PCA 2011 |
| Serial | 3300000266BD1580EFA75CD6D3000000000266 |
| Valid from | 2020-03-04 18:30 UTC |
| Valid until | 2021-03-03 18:30 UTC (expired) |
| Signature validity | Not verified |
Engine angr, status completed, 46 paths explored at a maximum depth of 46. Vulnerability classes reached: 0. Exploitable paths: 1.
Based on DriverShield static and dynamic analysis, appid.sys shows some suspicious signals and warrants manual review. Its composite risk score is 58/100 (verdict: suspicious). Always validate findings independently before acting.
appid.sys has a DriverShield composite risk score of 58/100, placing it in the suspicious verdict band. SHA256: 7031fec4cebddad6e55df0da8d17c1c5eec92899a816130d1f68916bda39e03a.
appid.sys is a Windows kernel-mode driver (.sys) analyzed by DriverShield for vulnerabilities, BYOVD abuse potential, and malware indicators. It is code-signed by Microsoft Windows.
Related: Other drivers signed by Microsoft Windows · What an IOCTL dispatch code is · How YARA matching feeds the score · BYOVD research index · full driver database · CVE library · code signing atlas