ACE-CORE.sys - Suspicious (35/100) - DriverShield Analysis

Analysis of ACE-CORE.sys: suspicious verdict, risk score 35/100. 0 YARA matches, 0/76 multi-engine detections. SHA256 565873323fb74aa1. Kernel imports, IOCTL codes, MITRE ATT&CK, and code-signing details.

ACE-CORE.sys - Analysis Report

DriverShield analyzed the Windows kernel driver ACE-CORE.sys and assigned a verdict of Suspicious with a composite risk score of 35/100, indicating some risk signals warranting review (30-59 band).

VerdictSuspicious (35/100)
YARA matches0
Multi-engine detections0 / 76
File size3917936 bytes
Code-signing signerMicrosoft Windows Hardware Compatibility Publisher
Analyzed2026-09-10
SHA256565873323fb74aa138db1c157ef50e68942a11bf0d244bb4129390ae05e7c1ff
SHA17e169549cfafd1a804e671bc18d985830b57b314
MD5e7c8c8c55bdfd8c74bdd4136c860fa0f

Driver identity

Version resource data embedded in the ACE-CORE.sys PE header, as extracted by the analysis engine.

File descriptionACE-CORE32 System Driver
ProductAnti-Cheat Expert
CompanyANTICHEATEXPERT.COM
Internal nameACE-CORE32
File version24.3.2511.316
Copyright© AntiCheatExpert.com Limited. All Rights Reserved.

How the 35/100 score breaks down

Each component is scored 0-100 and then weighted into the composite. See the analysis methodology for the exact formula.

ComponentSub-score
Multi-engine consensus0 / 100
YARA signature matches0 / 100
Dangerous kernel imports100 / 100
IOCTL dispatch surface100 / 100
Known-vulnerable corpus0 / 100
Code-signing state80 / 100
Packing and entropy0 / 100
Dynamic behaviour0 / 100
CVE cross-reference0 / 100

Kernel imports (33)

Kernel-mode APIs resolved from the Import Address Table of ACE-CORE.sys, ranked by exploitation relevance.

APIRiskWhy it matters
MmMapLockedPagesSpecifyCachecriticalHighly dangerous - potential for arbitrary code execution, memory corruption, or process termination
MmGetSystemRoutineAddresshighPotentially dangerous - could be used for privilege escalation or security bypass
PsLookupProcessByProcessIdhighPotentially dangerous - could be used for privilege escalation or security bypass
ZwQuerySystemInformationmediumModerate risk - system modification capability
ZwCreateKeymediumModerate risk - system modification capability
KeBugCheckExmediumModerate risk - system modification capability
ZwSetValueKeymediumModerate risk - system modification capability
ObOpenObjectByPointermediumModerate risk - system modification capability
ZwDeleteKeymediumModerate risk - system modification capability
ObReferenceObjectByHandlemediumModerate risk - system modification capability
ZwDeleteFilemediumModerate risk - system modification capability
ProbeForReadlowStandard kernel API - generally benign
IoBuildDeviceIoControlRequestlowStandard kernel API - generally benign
ZwReadFilelowStandard kernel API - generally benign
ZwCloselowStandard kernel API - generally benign
IoCreateDeviceSecurelowStandard kernel API - generally benign
RtlInitAnsiStringlowStandard kernel API - generally benign
IoCreateDevicelowStandard kernel API - generally benign
ZwQueryInformationFilelowStandard kernel API - generally benign
IoDeleteDevicelowStandard kernel API - generally benign
ZwQueryValueKeylowStandard kernel API - generally benign
ExAllocatePoolWithTaglowStandard kernel API - generally benign
IofCompleteRequestlowStandard kernel API - generally benign
DbgPrintExlowStandard kernel API - generally benign
IoDeleteSymbolicLinklowStandard kernel API - generally benign
ZwOpenKeylowStandard kernel API - generally benign
KeWaitForSingleObjectlowStandard kernel API - generally benign
KeSetEventlowStandard kernel API - generally benign

Showing the 28 highest-relevance imports of 33 resolved.

IOCTL dispatch codes (40)

Control codes reachable through the driver dispatch routine. Codes tied to published exploit code are flagged, since they are the primary Bring Your Own Vulnerable Driver (BYOVD) entry points.

CodeSeverityTransferDescription
0x9876058BhighMETHOD_NEITHERCUSTOM_PROCESS Function #354
0x0080840FhighMETHOD_NEITHERFILE_DEVICE_CUSTOM Function #259
0x0080818BhighMETHOD_NEITHERFILE_DEVICE_CUSTOM Function #98
0x00808D8BhighMETHOD_NEITHERFILE_DEVICE_CUSTOM Function #866
0x0022F49BhighMETHOD_NEITHERFILE_DEVICE_UNKNOWN Function #3366
0x9C40F36BhighMETHOD_NEITHERCUSTOM_LENOVO Function #3290
0x0080B3FFhighMETHOD_NEITHERFILE_DEVICE_CUSTOM Function #3327
0x0080B5FFhighMETHOD_NEITHERFILE_DEVICE_CUSTOM Function #3455
0x0080838FhighMETHOD_NEITHERFILE_DEVICE_CUSTOM Function #227
0x00343B8BhighMETHOD_NEITHERFILE_DEVICE_DISK Function #3810
0x0022880FhighMETHOD_NEITHERFILE_DEVICE_UNKNOWN Function #515
0x0080857FhighMETHOD_NEITHERFILE_DEVICE_CUSTOM Function #351
0x9C400503highMETHOD_NEITHERCUSTOM_LENOVO Function #320
0xC3501503highMETHOD_NEITHERCUSTOM_MSI Function #1344
0x00340503highMETHOD_NEITHERFILE_DEVICE_DISK Function #320
0x9C400D03highMETHOD_NEITHERCUSTOM_LENOVO Function #832
0x0022026FhighMETHOD_NEITHERFILE_DEVICE_UNKNOWN Function #155
0x00220A57highMETHOD_NEITHERFILE_DEVICE_UNKNOWN Function #661
0x0022103BhighMETHOD_NEITHERFILE_DEVICE_UNKNOWN Function #1038
0x0022123BhighMETHOD_NEITHERFILE_DEVICE_UNKNOWN Function #1166
0x0022142FhighMETHOD_NEITHERFILE_DEVICE_UNKNOWN Function #1291
0x0022162BhighMETHOD_NEITHERFILE_DEVICE_UNKNOWN Function #1418
0x00222207highMETHOD_NEITHERFILE_DEVICE_UNKNOWN Function #2177
0x002227FBhighMETHOD_NEITHERFILE_DEVICE_UNKNOWN Function #2558

Showing 24 of 40 extracted control codes.

PE sections

Section layout and Shannon entropy. High entropy in a code section is a packing or encryption indicator.

SectionVirtual sizeRaw sizeEntropyFlags
.text0x239390x23A004.13CODE, EXEC, READ
.rdata0x64200x66005.16IDATA, READ
.data0x10ABC80x0A001.93IDATA, READ, WRITE
.pdata0x2FAC0x30005.44IDATA, READ
.CRT0x00D80x02001.41IDATA, READ
.gfids0x00040x02000.02IDATA, READ
PAGE0x18FD0x1A006.27CODE, EXEC, READ
INIT0x12D60x14005.02CODE, EXEC, READ, DISCARD
.rsrc0x03E80x04003.37IDATA, READ, DISCARD
.reloc0x00E00x02002.88IDATA, READ, DISCARD
.tvm00x3860000x3860006.88CODE, EXEC, READ

Exploit mitigations

Control Flow GuardNot enabled
ASLREnabled
DEPEnabled
Integrity checkEnforced
Mitigation score60 / 100

MITRE ATT&CK techniques (14)

Techniques this driver could enable if loaded by an adversary.

IDTechniqueTactic
T1003.001OS Credential Dumping: LSASS MemoryCredential Access
T1055.001Process Injection: DLL InjectionDefense Evasion
T1055.012Process HollowingDefense Evasion
T1068Exploitation for Privilege EscalationPrivilege Escalation
T1071Application Layer ProtocolCommand and Control
T1112Modify RegistryDefense Evasion
T1211Exploitation for Defense EvasionDefense Evasion
T1489Service StopImpact
T1543.003Windows ServicePersistence
T1547.001Registry Run KeysPersistence
T1553.002Subvert Trust Controls: Code SigningDefense Evasion
T1562.001Impair Defenses: Disable/Modify ToolsDefense Evasion
T1569.002Service ExecutionExecution
T1652Device Driver DiscoveryDiscovery

Code-signing chain

SignerMicrosoft Windows Hardware Compatibility Publisher
Signer organisationMicrosoft Corporation
IssuerMicrosoft Windows Third Party Component CA 2014
Serial3300000074FF3D4A9E7C401E86000000000074
Valid from2025-07-16 20:48 UTC
Valid until2026-07-14 20:48 UTC (expired)
Signature validityNot verified

Symbolic execution

Engine angr, status completed, 100 paths explored at a maximum depth of 100. Vulnerability classes reached: 0. Exploitable paths: 0.

Frequently asked questions about ACE-CORE.sys

Is ACE-CORE.sys safe?

Based on DriverShield static and dynamic analysis, ACE-CORE.sys shows some suspicious signals and warrants manual review. Its composite risk score is 35/100 (verdict: suspicious). Always validate findings independently before acting.

What is the risk score of ACE-CORE.sys?

ACE-CORE.sys has a DriverShield composite risk score of 35/100, placing it in the suspicious verdict band. SHA256: 565873323fb74aa138db1c157ef50e68942a11bf0d244bb4129390ae05e7c1ff.

What is ACE-CORE.sys?

ACE-CORE.sys is a Windows kernel-mode driver (.sys) analyzed by DriverShield for vulnerabilities, BYOVD abuse potential, and malware indicators. It is code-signed by Microsoft Windows Hardware Compatibility Publisher.

Related: Other drivers signed by Microsoft Windows Hardware Compatibility Publisher · What an IOCTL dispatch code is · BYOVD research index · full driver database · CVE library · code signing atlas


DriverShield © 2025-2026 · Terms · Privacy · Contact