Analysis of ACE-GAME.sys: vulnerable verdict, risk score 72/100. 2 YARA matches, 0/75 multi-engine detections. SHA256 6aaac19bb58b7cea. Kernel imports, IOCTL codes, MITRE ATT&CK, and code-signing details.
DriverShield analyzed the Windows kernel driver ACE-GAME.sys and assigned a verdict of Vulnerable with a composite risk score of 72/100, indicating a known or likely vulnerability surface (60-79 band).
| Verdict | Vulnerable (72/100) |
| YARA matches | 2 |
| Multi-engine detections | 0 / 75 |
| File size | 2067800 bytes |
| Code-signing signer | DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1 |
| Analyzed | 2026-08-05 |
| SHA256 | 6aaac19bb58b7ceaa4af4f7e7a0b2a52e59bd55bc3379335a31480cb5eaefb37 |
| SHA1 | 03fa9521d0ee4e6f0f57506b45ba9b5bc6e2e18b |
| MD5 | 7cc5218fe48674fe9a7b33c5fb161ee0 |
Version resource data embedded in the ACE-GAME.sys PE header, as extracted by the analysis engine.
| File description | ACE-GAME NT Driver |
|---|---|
| Product | Anti-Cheat Expert |
| Company | ANTICHEATEXPERT.COM |
| Internal name | ACE-GAME |
| File version | 1.0.2508.1 |
| Copyright | © AntiCheatExpert.com Limited. All Rights Reserved. |
Each component is scored 0-100 and then weighted into the composite. See the analysis methodology for the exact formula.
| Component | Sub-score |
|---|---|
| Multi-engine consensus | 0 / 100 |
| YARA signature matches | 35 / 100 |
| Dangerous kernel imports | 100 / 100 |
| IOCTL dispatch surface | 100 / 100 |
| Known-vulnerable corpus | 0 / 100 |
| Code-signing state | 0 / 100 |
| Packing and entropy | 0 / 100 |
| Dynamic behaviour | 0 / 100 |
| CVE cross-reference | 0 / 100 |
Kernel-mode APIs resolved from the Import Address Table of ACE-GAME.sys, ranked by exploitation relevance.
| API | Risk | Why it matters |
|---|---|---|
| MmMapLockedPagesSpecifyCache | critical | Highly dangerous - potential for arbitrary code execution, memory corruption, or process termination |
| MmMapIoSpace | critical | Highly dangerous - potential for arbitrary code execution, memory corruption, or process termination |
| ZwMapViewOfSection | critical | Highly dangerous - potential for arbitrary code execution, memory corruption, or process termination |
| ZwTerminateProcess | critical | Highly dangerous - potential for arbitrary code execution, memory corruption, or process termination |
| HalSetBusDataByOffset | high | Potentially dangerous - could be used for privilege escalation or security bypass |
| MmGetPhysicalAddress | high | Potentially dangerous - could be used for privilege escalation or security bypass |
| MmAllocateContiguousMemory | high | Potentially dangerous - could be used for privilege escalation or security bypass |
| ObRegisterCallbacks | high | Potentially dangerous - could be used for privilege escalation or security bypass |
| PsSetCreateProcessNotifyRoutineEx | high | Potentially dangerous - could be used for privilege escalation or security bypass |
| PsSetCreateProcessNotifyRoutine | high | Potentially dangerous - could be used for privilege escalation or security bypass |
| MmGetSystemRoutineAddress | high | Potentially dangerous - could be used for privilege escalation or security bypass |
| HalGetBusDataByOffset | high | Potentially dangerous - could be used for privilege escalation or security bypass |
| ZwOpenProcess | high | Potentially dangerous - could be used for privilege escalation or security bypass |
| PsLookupProcessByProcessId | high | Potentially dangerous - could be used for privilege escalation or security bypass |
| ObOpenObjectByPointer | medium | Moderate risk - system modification capability |
| CmRegisterCallback | medium | Moderate risk - system modification capability |
| MmUnmapIoSpace | medium | Moderate risk - system modification capability |
| ZwQuerySystemInformation | medium | Moderate risk - system modification capability |
| PsSetLoadImageNotifyRoutine | medium | Moderate risk - system modification capability |
| KeBugCheckEx | medium | Moderate risk - system modification capability |
| PsSetCreateThreadNotifyRoutine | medium | Moderate risk - system modification capability |
| ZwDeleteKey | medium | Moderate risk - system modification capability |
| ObReferenceObjectByHandle | medium | Moderate risk - system modification capability |
| ZwSetInformationFile | medium | Moderate risk - system modification capability |
| ZwCreateKey | medium | Moderate risk - system modification capability |
| ZwSetValueKey | medium | Moderate risk - system modification capability |
| ZwDeleteFile | medium | Moderate risk - system modification capability |
| ZwWriteFile | medium | Moderate risk - system modification capability |
Showing the 28 highest-relevance imports of 50 resolved.
Control codes reachable through the driver dispatch routine. Codes tied to published exploit code are flagged, since they are the primary Bring Your Own Vulnerable Driver (BYOVD) entry points.
| Code | Severity | Transfer | Description |
|---|---|---|---|
| 0x008087C7 | high | METHOD_NEITHER | FILE_DEVICE_CUSTOM Function #497 |
| 0x0080820B | high | METHOD_NEITHER | FILE_DEVICE_CUSTOM Function #130 |
| 0x0080E89F | high | METHOD_NEITHER | FILE_DEVICE_CUSTOM Function #2599 |
| 0x0080840F | high | METHOD_NEITHER | FILE_DEVICE_CUSTOM Function #259 |
| 0x0022641F | high | METHOD_NEITHER | FILE_DEVICE_UNKNOWN Function #2311 |
| 0x00227423 | high | METHOD_NEITHER | FILE_DEVICE_UNKNOWN Function #3336 |
| 0x0080B5FF | high | METHOD_NEITHER | FILE_DEVICE_CUSTOM Function #3455 |
| 0x0080B3FF | high | METHOD_NEITHER | FILE_DEVICE_CUSTOM Function #3327 |
| 0x0080838F | high | METHOD_NEITHER | FILE_DEVICE_CUSTOM Function #227 |
| 0x82730D8B | high | METHOD_NEITHER | CUSTOM_VIRAGT Function #866 |
| 0x0080B1FF | high | METHOD_NEITHER | FILE_DEVICE_CUSTOM Function #3199 |
| 0x002200F0 | medium | METHOD_BUFFERED | FILE_DEVICE_UNKNOWN Function #60 |
| 0x0080C481 | medium | METHOD_IN_DIRECT | FILE_DEVICE_CUSTOM Function #288 |
| 0x008000B9 | medium | METHOD_IN_DIRECT | FILE_DEVICE_CUSTOM Function #46 |
| 0x0080BA41 | medium | METHOD_IN_DIRECT | FILE_DEVICE_CUSTOM Function #3728 |
| 0x0080249C | medium | METHOD_BUFFERED | FILE_DEVICE_CUSTOM Function #2343 |
| 0x00802484 | medium | METHOD_BUFFERED | FILE_DEVICE_CUSTOM Function #2337 |
| 0x0080248C | medium | METHOD_BUFFERED | FILE_DEVICE_CUSTOM Function #2339 |
| 0x00802494 | medium | METHOD_BUFFERED | FILE_DEVICE_CUSTOM Function #2341 |
| 0x0080B841 | medium | METHOD_IN_DIRECT | FILE_DEVICE_CUSTOM Function #3600 |
| 0x008024BC | medium | METHOD_BUFFERED | FILE_DEVICE_CUSTOM Function #2351 |
| 0x008076A6 | medium | METHOD_OUT_DIRECT | FILE_DEVICE_CUSTOM Function #3497 |
| 0x82734839 | medium | METHOD_IN_DIRECT | CUSTOM_VIRAGT Function #526 |
| 0x0080858D | medium | METHOD_IN_DIRECT | FILE_DEVICE_CUSTOM Function #355 |
Showing 24 of 40 extracted control codes.
Section layout and Shannon entropy. High entropy in a code section is a packing or encryption indicator.
| Section | Virtual size | Raw size | Entropy | Flags |
|---|---|---|---|---|
| .text | 0x2BDC8 | 0x2BE00 | 5.67 | CODE, EXEC, READ |
| .rdata | 0x30C0 | 0x3200 | 5.45 | IDATA, READ |
| .data | 0x15970 | 0x0600 | 3.13 | IDATA, READ, WRITE |
| .pdata | 0x1C08 | 0x1E00 | 5.17 | IDATA, READ |
| .CRT | 0x0070 | 0x0200 | 0.84 | IDATA, READ |
| .gfids | 0x0004 | 0x0200 | 0.02 | IDATA, READ |
| PAGE | 0x02CF | 0x0400 | 4.85 | CODE, EXEC, READ |
| INIT | 0x12C8 | 0x1400 | 5.14 | CODE, EXEC, READ, DISCARD |
| .rsrc | 0x0350 | 0x0400 | 2.9 | IDATA, READ, DISCARD |
| .reloc | 0x0070 | 0x0200 | 1.33 | IDATA, READ, DISCARD |
| .tvm0 | 0x1C0000 | 0x1C0000 | 6.97 | CODE, EXEC, READ |
| Control Flow Guard | Not enabled |
|---|---|
| ASLR | Enabled |
| DEP | Enabled |
| Integrity check | Enforced |
| Mitigation score | 75 / 100 |
| Rule | Severity | Detects |
|---|---|---|
| SUSP_PhysMem | high | Physical memory mapping |
| SUSP_Callbacks | medium | Kernel callback registration |
Techniques this driver could enable if loaded by an adversary.
| ID | Technique | Tactic |
|---|---|---|
| T1003 | OS Credential Dumping | Credential Access |
| T1003.001 | OS Credential Dumping: LSASS Memory | Credential Access |
| T1006 | Direct Volume Access | Defense Evasion |
| T1014 | Rootkit | Defense Evasion |
| T1055.001 | Process Injection: DLL Injection | Defense Evasion |
| T1055.012 | Process Hollowing | Defense Evasion |
| T1068 | Exploitation for Privilege Escalation | Privilege Escalation |
| T1071 | Application Layer Protocol | Command and Control |
| T1112 | Modify Registry | Defense Evasion |
| T1211 | Exploitation for Defense Evasion | Defense Evasion |
| T1489 | Service Stop | Impact |
| T1542.001 | Pre-OS Boot: System Firmware | Persistence |
| T1543.003 | Windows Service | Persistence |
| T1547.001 | Registry Run Keys | Persistence |
| T1553.002 | Subvert Trust Controls: Code Signing | Defense Evasion |
| T1562.001 | Disable/Modify Tools | Defense Evasion |
| T1562.006 | Indicator Blocking | Defense Evasion |
| T1564.001 | Hidden Files and Directories | Defense Evasion |
| T1569.002 | Service Execution | Execution |
| T1601 | Modify System Image | Defense Evasion |
| T1652 | Device Driver Discovery | Discovery |
| Signer | DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1 |
|---|---|
| Signer organisation | DigiCert, Inc. |
| Issuer | DigiCert Trusted Root G4 |
| Serial | 8AD40B260D29C4C9F5ECDA9BD93AED9 |
| Valid from | 2021-04-29 00:00 UTC |
| Valid until | 2036-04-28 23:59 UTC |
| Signature validity | Verified |
Engine angr, status completed, 66 paths explored at a maximum depth of 66. Vulnerability classes reached: 0. Exploitable paths: 0.
Based on DriverShield static and dynamic analysis, ACE-GAME.sys is flagged as vulnerable and is a potential Bring Your Own Vulnerable Driver (BYOVD) risk. Its composite risk score is 72/100 (verdict: vulnerable). Always validate findings independently before acting.
ACE-GAME.sys has a DriverShield composite risk score of 72/100, placing it in the vulnerable verdict band. SHA256: 6aaac19bb58b7ceaa4af4f7e7a0b2a52e59bd55bc3379335a31480cb5eaefb37.
ACE-GAME.sys is a Windows kernel-mode driver (.sys) analyzed by DriverShield for vulnerabilities, BYOVD abuse potential, and malware indicators. It is code-signed by DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1.
Related: Other drivers signed by DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1 · What an IOCTL dispatch code is · How YARA matching feeds the score · BYOVD research index · full driver database · CVE library · code signing atlas