megasas.sys - Clean (9/100) - DriverShield Analysis

Analysis of megasas.sys: clean verdict, risk score 9/100. 0 YARA matches. SHA256 9041fdeb932f2cbb. Kernel imports, IOCTL codes, MITRE ATT&CK, and code-signing details.

megasas.sys - Analysis Report

DriverShield analyzed the Windows kernel driver megasas.sys and assigned a verdict of Clean with a composite risk score of 9/100, indicating no notable risk signals (0-29 band).

VerdictClean (9/100)
YARA matches0
File size59704 bytes
Code-signing signerMicrosoft Windows
Analyzed2026-03-22
SHA2569041fdeb932f2cbbce4a017256c81b3733604403aa343d4532910436e8288ca9
SHA1986e6ef1cb034e62ff354fffb87c61c063d127ad
MD5ce4b01081b8fd211a7a34219d5e8154a

Driver identity

Version resource data embedded in the megasas.sys PE header, as extracted by the analysis engine.

File descriptionMEGASAS RAID Controller Driver for Windows
ProductMEGASAS RAID Controller Driver for Windows
CompanyAvago Technologies
Original filenamemegasas2.sys
Internal namemegasas2.sys
File version6.706.06.00 (NT.150223-1854)
CopyrightCopyright © Avago Technologies2013

How the 9/100 score breaks down

Each component is scored 0-100 and then weighted into the composite. See the analysis methodology for the exact formula.

ComponentSub-score
Multi-engine consensus0 / 100
YARA signature matches0 / 100
Dangerous kernel imports0 / 100
IOCTL dispatch surface42 / 100
Known-vulnerable corpus0 / 100
Code-signing state80 / 100
Packing and entropy0 / 100
Dynamic behaviour0 / 100
CVE cross-reference0 / 100

IOCTL dispatch codes (14)

Control codes reachable through the driver dispatch routine. Codes tied to published exploit code are flagged, since they are the primary Bring Your Own Vulnerable Driver (BYOVD) entry points.

CodeSeverityTransferDescription
0x0080878BhighMETHOD_NEITHERFILE_DEVICE_CUSTOM Function #482
0x00808F8BhighMETHOD_NEITHERFILE_DEVICE_CUSTOM Function #994
0x00808B8BhighMETHOD_NEITHERFILE_DEVICE_CUSTOM Function #738
0x0080898BhighMETHOD_NEITHERFILE_DEVICE_CUSTOM Function #610
0x0080818BhighMETHOD_NEITHERFILE_DEVICE_CUSTOM Function #98
0x0080918BhighMETHOD_NEITHERFILE_DEVICE_CUSTOM Function #1122
0x0080838BhighMETHOD_NEITHERFILE_DEVICE_CUSTOM Function #226
0x002200F0mediumMETHOD_BUFFEREDFILE_DEVICE_UNKNOWN Function #60
0x0022E8D9mediumMETHOD_IN_DIRECTFILE_DEVICE_UNKNOWN Function #2614
0x0022BA05mediumMETHOD_IN_DIRECTFILE_DEVICE_UNKNOWN Function #3713
0x0080248CmediumMETHOD_BUFFEREDFILE_DEVICE_CUSTOM Function #2339
0x0080E900mediumMETHOD_BUFFEREDFILE_DEVICE_CUSTOM Function #2624
0x0080FD81mediumMETHOD_IN_DIRECTFILE_DEVICE_CUSTOM Function #3936
0x003403A0mediumMETHOD_BUFFEREDFILE_DEVICE_DISK Function #232

PE sections

Section layout and Shannon entropy. High entropy in a code section is a packing or encryption indicator.

SectionVirtual sizeRaw sizeEntropyFlags
.text0x9B6A0x9C006.39CODE, EXEC, READ
.rdata0x09540x0A004.62IDATA, READ
.data0x05B10x06002.98IDATA, READ, WRITE
.pdata0x04A40x06003.59IDATA, READ
.idata0x03FC0x04004.06IDATA, READ
INIT0x01150x02003.57CODE, EXEC, READ, DISCARD
GFIDS0x00EC0x02001.87IDATA, READ, DISCARD
.rsrc0x07200x08005.05IDATA, READ, DISCARD
.reloc0x00E80x02002.75IDATA, READ, DISCARD

Exploit mitigations

Control Flow GuardEnabled
ASLREnabled
DEPEnabled
Integrity checkNot enforced
Mitigation score85 / 100

MITRE ATT&CK techniques (3)

Techniques this driver could enable if loaded by an adversary.

IDTechniqueTactic
T1071Application Layer ProtocolCommand and Control
T1543.003Windows ServicePersistence
T1652Device Driver DiscoveryDiscovery

Code-signing chain

SignerMicrosoft Windows
Signer organisationMicrosoft Corporation
IssuerMicrosoft Windows Production PCA 2011
Serial330000023241FB59996DCC4DFF000000000232
Valid from2019-05-02 21:24 UTC
Valid until2020-05-02 21:24 UTC (expired)
Signature validityNot verified

Symbolic execution

Engine angr, status no_findings, 0 paths explored at a maximum depth of 0. Vulnerability classes reached: 0. Exploitable paths: 0.

Frequently asked questions about megasas.sys

Is megasas.sys safe?

Based on DriverShield static and dynamic analysis, megasas.sys is assessed as clean, with no notable risk signals. Its composite risk score is 9/100 (verdict: clean). Always validate findings independently before acting.

What is the risk score of megasas.sys?

megasas.sys has a DriverShield composite risk score of 9/100, placing it in the clean verdict band. SHA256: 9041fdeb932f2cbbce4a017256c81b3733604403aa343d4532910436e8288ca9.

What is megasas.sys?

megasas.sys is a Windows kernel-mode driver (.sys) analyzed by DriverShield for vulnerabilities, BYOVD abuse potential, and malware indicators. It is code-signed by Microsoft Windows.

Related: Other drivers signed by Microsoft Windows · What an IOCTL dispatch code is · BYOVD research index · full driver database · CVE library · code signing atlas


DriverShield © 2025-2026 · Terms · Privacy · Contact