pylonGEV.sys - Clean (21/100) - DriverShield Analysis

Analysis of pylonGEV.sys: clean verdict, risk score 21/100. 0 YARA matches, 0/75 multi-engine detections. SHA256 c4580b514fc095c1. Kernel imports, IOCTL codes, MITRE ATT&CK, and code-signing details.

pylonGEV.sys - Analysis Report

DriverShield analyzed the Windows kernel driver pylonGEV.sys and assigned a verdict of Clean with a composite risk score of 21/100, indicating no notable risk signals (0-29 band).

VerdictClean (21/100)
YARA matches0
Multi-engine detections0 / 75
File size87816 bytes
Code-signing signerDigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1
Analyzed2026-07-09
SHA256c4580b514fc095c1d64e03b2816a01aa1e925e780aefc2e236efc4b20b7cb4ae
SHA1595403578f7e8ae7c987005a78d9d2d0138c6cce
MD5b6d4f79f1c385544720dc04b6bff7b10

Driver identity

Version resource data embedded in the pylonGEV.sys PE header, as extracted by the analysis engine.

File descriptionpylon GigE Vision Driver for NDIS 6
ProductpylonGEV NDIS 6 Driver
CompanyBasler AG
Original filenamepylonGEV.sys
Internal namepylonGEV.sys
File version5.4.0.1200
CopyrightCopyright (c) 2016-2023 Basler AG

How the 21/100 score breaks down

Each component is scored 0-100 and then weighted into the composite. See the analysis methodology for the exact formula.

ComponentSub-score
Multi-engine consensus0 / 100
YARA signature matches0 / 100
Dangerous kernel imports72 / 100
IOCTL dispatch surface60 / 100
Known-vulnerable corpus0 / 100
Code-signing state0 / 100
Packing and entropy0 / 100
Dynamic behaviour0 / 100
CVE cross-reference0 / 100

Kernel imports (8)

Kernel-mode APIs resolved from the Import Address Table of pylonGEV.sys, ranked by exploitation relevance.

APIRiskWhy it matters
MmMapLockedPagesSpecifyCachecriticalHighly dangerous - potential for arbitrary code execution, memory corruption, or process termination
MmGetSystemRoutineAddresshighPotentially dangerous - could be used for privilege escalation or security bypass
ObReferenceObjectByHandlemediumModerate risk - system modification capability
KeBugCheckExmediumModerate risk - system modification capability
IofCompleteRequestlowStandard kernel API - generally benign
ExAllocatePoolWithTaglowStandard kernel API - generally benign
RtlInitUnicodeStringlowStandard kernel API - generally benign
KeSetEventlowStandard kernel API - generally benign

IOCTL dispatch codes (20)

Control codes reachable through the driver dispatch routine. Codes tied to published exploit code are flagged, since they are the primary Bring Your Own Vulnerable Driver (BYOVD) entry points.

CodeSeverityTransferDescription
0x0034BBFFhighMETHOD_NEITHERFILE_DEVICE_DISK Function #3839
0x0080878BhighMETHOD_NEITHERFILE_DEVICE_CUSTOM Function #482
0x002200F0mediumMETHOD_BUFFEREDFILE_DEVICE_UNKNOWN Function #60
0x0022BA00mediumMETHOD_BUFFEREDFILE_DEVICE_UNKNOWN Function #3712
0x0034BA58mediumMETHOD_BUFFEREDFILE_DEVICE_DISK Function #3734
0x0080249CmediumMETHOD_BUFFEREDFILE_DEVICE_CUSTOM Function #2343
0x0080D315mediumMETHOD_IN_DIRECTFILE_DEVICE_CUSTOM Function #1221
0x00804305mediumMETHOD_IN_DIRECTFILE_DEVICE_CUSTOM Function #193
0x003437E8mediumMETHOD_BUFFEREDFILE_DEVICE_DISK Function #3578
0x0080248CmediumMETHOD_BUFFEREDFILE_DEVICE_CUSTOM Function #2339
0x0022B705mediumMETHOD_IN_DIRECTFILE_DEVICE_UNKNOWN Function #3521
0x00227705mediumMETHOD_IN_DIRECTFILE_DEVICE_UNKNOWN Function #3521
0x0034D73DmediumMETHOD_IN_DIRECTFILE_DEVICE_DISK Function #1487
0x0034230DmediumMETHOD_IN_DIRECTFILE_DEVICE_DISK Function #2243
0x008024ACmediumMETHOD_BUFFEREDFILE_DEVICE_CUSTOM Function #2347
0x00223418mediumMETHOD_BUFFEREDFILE_DEVICE_UNKNOWN Function #3334
0x0034002DmediumMETHOD_IN_DIRECTFILE_DEVICE_DISK Function #11
0x0034032CmediumMETHOD_BUFFEREDFILE_DEVICE_DISK Function #203
0x00220068mediumMETHOD_BUFFEREDFILE_DEVICE_UNKNOWN Function #26
0x00340025mediumMETHOD_IN_DIRECTFILE_DEVICE_DISK Function #9

PE sections

Section layout and Shannon entropy. High entropy in a code section is a packing or encryption indicator.

SectionVirtual sizeRaw sizeEntropyFlags
.text0xCCE90xCE006.38CODE, EXEC, READ
.rdata0x10280x12004.76IDATA, READ
.data0x01C80x02000.37IDATA, READ, WRITE
.pdata0x07B00x08004.46IDATA, READ
PAGE0x055C0x06005.64CODE, EXEC, READ
INIT0x10480x12005.63CODE, EXEC, READ, DISCARD
.rsrc0x06A00x08003.16IDATA, READ, DISCARD
.reloc0x003C0x02000.77IDATA, READ, DISCARD

Exploit mitigations

Control Flow GuardEnabled
ASLREnabled
DEPEnabled
Integrity checkNot enforced
Mitigation score100 / 100

MITRE ATT&CK techniques (9)

Techniques this driver could enable if loaded by an adversary.

IDTechniqueTactic
T1003.001OS Credential Dumping: LSASS MemoryCredential Access
T1055.012Process HollowingDefense Evasion
T1068Exploitation for Privilege EscalationPrivilege Escalation
T1071Application Layer ProtocolCommand and Control
T1211Exploitation for Defense EvasionDefense Evasion
T1543.003Windows ServicePersistence
T1553.002Subvert Trust Controls: Code SigningDefense Evasion
T1569.002Service ExecutionExecution
T1652Device Driver DiscoveryDiscovery

Code-signing chain

SignerDigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1
Signer organisationDigiCert, Inc.
IssuerDigiCert Trusted Root G4
Serial8AD40B260D29C4C9F5ECDA9BD93AED9
Valid from2021-04-29 00:00 UTC
Valid until2036-04-28 23:59 UTC
Signature validityVerified

Symbolic execution

Engine angr, status completed, 100 paths explored at a maximum depth of 100. Vulnerability classes reached: 0. Exploitable paths: 1.

Frequently asked questions about pylonGEV.sys

Is pylonGEV.sys safe?

Based on DriverShield static and dynamic analysis, pylonGEV.sys is assessed as clean, with no notable risk signals. Its composite risk score is 21/100 (verdict: clean). Always validate findings independently before acting.

What is the risk score of pylonGEV.sys?

pylonGEV.sys has a DriverShield composite risk score of 21/100, placing it in the clean verdict band. SHA256: c4580b514fc095c1d64e03b2816a01aa1e925e780aefc2e236efc4b20b7cb4ae.

What is pylonGEV.sys?

pylonGEV.sys is a Windows kernel-mode driver (.sys) analyzed by DriverShield for vulnerabilities, BYOVD abuse potential, and malware indicators. It is code-signed by DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1.

Related: Other drivers signed by DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1 · What an IOCTL dispatch code is · BYOVD research index · full driver database · CVE library · code signing atlas


DriverShield © 2025-2026 · Terms · Privacy · Contact