hidi2c.sys - Clean (15/100) - DriverShield Analysis

Analysis of hidi2c.sys: clean verdict, risk score 15/100. 0 YARA matches. SHA256 c161d2122638690c. Kernel imports, IOCTL codes, MITRE ATT&CK, and code-signing details.

hidi2c.sys - Analysis Report

DriverShield analyzed the Windows kernel driver hidi2c.sys and assigned a verdict of Clean with a composite risk score of 15/100, indicating no notable risk signals (0-29 band).

VerdictClean (15/100)
YARA matches0
File size57344 bytes
Analyzed2026-03-22
SHA256c161d2122638690ce4da546ce8827b4bbd96747a4a7d799a776fec5bc57d1582
SHA1575fd63047be29a728897aaa354f48629b5922fa
MD51e129e905072a79282d6cc929284dfe5

Driver identity

Version resource data embedded in the hidi2c.sys PE header, as extracted by the analysis engine.

File descriptionI2C HID Miniport Driver
ProductMicrosoft® Windows® Operating System
CompanyMicrosoft Corporation
Original filenamehidi2c.sys
Internal namehidi2c.sys
File version10.0.19041.1 (WinBuild.160101.0800)
Copyright© Microsoft Corporation. All rights reserved.

How the 15/100 score breaks down

Each component is scored 0-100 and then weighted into the composite. See the analysis methodology for the exact formula.

ComponentSub-score
Multi-engine consensus0 / 100
YARA signature matches0 / 100
Dangerous kernel imports30 / 100
IOCTL dispatch surface57 / 100
Known-vulnerable corpus0 / 100
Code-signing state50 / 100
Packing and entropy0 / 100
Dynamic behaviour0 / 100
CVE cross-reference0 / 100

Kernel imports (4)

Kernel-mode APIs resolved from the Import Address Table of hidi2c.sys, ranked by exploitation relevance.

APIRiskWhy it matters
MmGetSystemRoutineAddresshighPotentially dangerous - could be used for privilege escalation or security bypass
DbgPrintExlowStandard kernel API - generally benign
RtlInitUnicodeStringlowStandard kernel API - generally benign
ExAllocatePoolWithTaglowStandard kernel API - generally benign

IOCTL dispatch codes (19)

Control codes reachable through the driver dispatch routine. Codes tied to published exploit code are flagged, since they are the primary Bring Your Own Vulnerable Driver (BYOVD) entry points.

CodeSeverityTransferDescription
0x00808F8BhighMETHOD_NEITHERFILE_DEVICE_CUSTOM Function #994
0x0080B68BhighMETHOD_NEITHERFILE_DEVICE_CUSTOM Function #3490
0x0022BB07highMETHOD_NEITHERFILE_DEVICE_UNKNOWN Function #3777
0x002200F0mediumMETHOD_BUFFEREDFILE_DEVICE_UNKNOWN Function #60
0x00802484mediumMETHOD_BUFFEREDFILE_DEVICE_CUSTOM Function #2337
0x00809B05mediumMETHOD_IN_DIRECTFILE_DEVICE_CUSTOM Function #1729
0x00808B48mediumMETHOD_BUFFEREDFILE_DEVICE_CUSTOM Function #722
0x0080AF89mediumMETHOD_IN_DIRECTFILE_DEVICE_CUSTOM Function #3042
0x00800315mediumMETHOD_IN_DIRECTFILE_DEVICE_CUSTOM Function #197
0x0022B941mediumMETHOD_IN_DIRECTFILE_DEVICE_UNKNOWN Function #3664
0x00343315mediumMETHOD_IN_DIRECTFILE_DEVICE_DISK Function #3269
0x0080CFE8mediumMETHOD_BUFFEREDFILE_DEVICE_CUSTOM Function #1018
0x00340036mediumMETHOD_OUT_DIRECTFILE_DEVICE_DISK Function #13
0x00346424mediumMETHOD_BUFFEREDFILE_DEVICE_DISK Function #2313
0x0022011DmediumMETHOD_IN_DIRECTFILE_DEVICE_UNKNOWN Function #71
0x00802494mediumMETHOD_BUFFEREDFILE_DEVICE_CUSTOM Function #2341
0x00228341mediumMETHOD_IN_DIRECTFILE_DEVICE_UNKNOWN Function #208
0x0080EC81mediumMETHOD_IN_DIRECTFILE_DEVICE_CUSTOM Function #2848
0x0034038CmediumMETHOD_BUFFEREDFILE_DEVICE_DISK Function #227

PE sections

Section layout and Shannon entropy. High entropy in a code section is a packing or encryption indicator.

SectionVirtual sizeRaw sizeEntropyFlags
.text0x7AE90x7C006.12CODE, EXEC, READ
.rdata0x17880x18005.54IDATA, READ
.data0x05200x02001.35IDATA, READ, WRITE
.pdata0x04B00x06003.65IDATA, READ
.idata0x04520x06003.28IDATA, READ
PAGE0x18D20x1A006.03CODE, EXEC, READ
INIT0x02A20x04004.42CODE, EXEC, READ, DISCARD
GFIDS0x00580x02000.81IDATA, READ, DISCARD
.rsrc0x15B80x16003.82IDATA, READ
.reloc0x03B40x04005.31IDATA, READ, DISCARD

Exploit mitigations

Control Flow GuardEnabled
ASLREnabled
DEPEnabled
Integrity checkNot enforced
Mitigation score80 / 100

MITRE ATT&CK techniques (6)

Techniques this driver could enable if loaded by an adversary.

IDTechniqueTactic
T1211Exploitation for Defense EvasionDefense Evasion
T1543.003Windows ServicePersistence
T1553.002Subvert Trust Controls: Code SigningDefense Evasion
T1553.006Code Signing Policy ModificationDefense Evasion
T1569.002Service ExecutionExecution
T1652Device Driver DiscoveryDiscovery

Symbolic execution

Engine angr, status no_findings, 0 paths explored at a maximum depth of 0. Vulnerability classes reached: 0. Exploitable paths: 0.

Frequently asked questions about hidi2c.sys

Is hidi2c.sys safe?

Based on DriverShield static and dynamic analysis, hidi2c.sys is assessed as clean, with no notable risk signals. Its composite risk score is 15/100 (verdict: clean). Always validate findings independently before acting.

What is the risk score of hidi2c.sys?

hidi2c.sys has a DriverShield composite risk score of 15/100, placing it in the clean verdict band. SHA256: c161d2122638690ce4da546ce8827b4bbd96747a4a7d799a776fec5bc57d1582.

What is hidi2c.sys?

hidi2c.sys is a Windows kernel-mode driver (.sys) analyzed by DriverShield for vulnerabilities, BYOVD abuse potential, and malware indicators.

Related: What an IOCTL dispatch code is · BYOVD research index · full driver database · CVE library · code signing atlas


DriverShield © 2025-2026 · Terms · Privacy · Contact