Vid.sys - Suspicious (58/100) - DriverShield Analysis

Analysis of Vid.sys: suspicious verdict, risk score 58/100. 2 YARA matches, 0/76 multi-engine detections. SHA256 dbeda17112616883. Kernel imports, IOCTL codes, MITRE ATT&CK, and code-signing details.

Vid.sys - Analysis Report

DriverShield analyzed the Windows kernel driver Vid.sys and assigned a verdict of Suspicious with a composite risk score of 58/100, indicating some risk signals warranting review (30-59 band).

VerdictSuspicious (58/100)
YARA matches2
Multi-engine detections0 / 76
File size910752 bytes
Code-signing signerMicrosoft Windows
Analyzed2026-04-01
SHA256dbeda1711261688305c3f093b9aa677758fbbf3cf90be878783b498633ea888b
SHA19ce9d02103dd5b6b39b604902cbfe7a62b81e24b
MD53e637c272b853d6a7a0bd1ad6eca6eb0

Driver identity

Version resource data embedded in the Vid.sys PE header, as extracted by the analysis engine.

File descriptionMicrosoft Hyper-V Virtualization Infrastructure Driver
ProductMicrosoft® Windows® Operating System
CompanyMicrosoft Corporation
Original filenamevid.sys
Internal namevid.sys
File version10.0.26100.7920 (WinBuild.160101.0800)
Copyright© Microsoft Corporation. All rights reserved.

How the 58/100 score breaks down

Each component is scored 0-100 and then weighted into the composite. See the analysis methodology for the exact formula.

ComponentSub-score
Multi-engine consensus0 / 100
YARA signature matches35 / 100
Dangerous kernel imports100 / 100
IOCTL dispatch surface100 / 100
Known-vulnerable corpus0 / 100
Code-signing state0 / 100
Packing and entropy0 / 100
Dynamic behaviour0 / 100
CVE cross-reference0 / 100

Kernel imports (24)

Kernel-mode APIs resolved from the Import Address Table of Vid.sys, ranked by exploitation relevance.

APIRiskWhy it matters
MmCopyVirtualMemorycriticalHighly dangerous - potential for arbitrary code execution, memory corruption, or process termination
MmMapLockedPagesSpecifyCachecriticalHighly dangerous - potential for arbitrary code execution, memory corruption, or process termination
ZwTerminateProcesscriticalHighly dangerous - potential for arbitrary code execution, memory corruption, or process termination
ZwSetSystemInformationhighPotentially dangerous - could be used for privilege escalation or security bypass
PsSetCreateProcessNotifyRoutinehighPotentially dangerous - could be used for privilege escalation or security bypass
MmGetSystemRoutineAddresshighPotentially dangerous - could be used for privilege escalation or security bypass
ObOpenObjectByPointermediumModerate risk - system modification capability
ZwQuerySystemInformationmediumModerate risk - system modification capability
ZwSetInformationFilemediumModerate risk - system modification capability
MmUnmapIoSpacemediumModerate risk - system modification capability
ObReferenceObjectByHandlemediumModerate risk - system modification capability
ZwCloselowStandard kernel API - generally benign
ExAllocatePool2lowStandard kernel API - generally benign
IofCompleteRequestlowStandard kernel API - generally benign
DbgPrintExlowStandard kernel API - generally benign
RtlInitUnicodeStringlowStandard kernel API - generally benign
ZwCreateFilelowStandard kernel API - generally benign
KeSetEventlowStandard kernel API - generally benign
ProbeForWritelowStandard kernel API - generally benign
KeDelayExecutionThreadlowStandard kernel API - generally benign
KeWaitForSingleObjectlowStandard kernel API - generally benign
ZwOpenFilelowStandard kernel API - generally benign
KeInitializeEventlowStandard kernel API - generally benign
PsGetCurrentProcesslowStandard kernel API - generally benign

IOCTL dispatch codes (40)

Control codes reachable through the driver dispatch routine. Codes tied to published exploit code are flagged, since they are the primary Bring Your Own Vulnerable Driver (BYOVD) entry points.

CodeSeverityTransferDescription
0x0080838BhighMETHOD_NEITHERFILE_DEVICE_CUSTOM Function #226
0x0080B9FFhighMETHOD_NEITHERFILE_DEVICE_CUSTOM Function #3711
0x0080860FhighMETHOD_NEITHERFILE_DEVICE_CUSTOM Function #387
0x0080878BhighMETHOD_NEITHERFILE_DEVICE_CUSTOM Function #482
0x00806583highMETHOD_NEITHERFILE_DEVICE_CUSTOM Function #2400
0x0022BFFFhighMETHOD_NEITHERFILE_DEVICE_UNKNOWN Function #4095
0x00221107highMETHOD_NEITHERFILE_DEVICE_UNKNOWN Function #1089
0x827338A3highMETHOD_NEITHERCUSTOM_VIRAGT Function #3624
0x0080858BhighMETHOD_NEITHERFILE_DEVICE_CUSTOM Function #354
0x00809D8BhighMETHOD_NEITHERFILE_DEVICE_CUSTOM Function #1890
0x0022BBFFhighMETHOD_NEITHERFILE_DEVICE_UNKNOWN Function #3839
0x00340033highMETHOD_NEITHERFILE_DEVICE_DISK Function #12
0x00800037highMETHOD_NEITHERFILE_DEVICE_CUSTOM Function #13
0x00800043highMETHOD_NEITHERFILE_DEVICE_CUSTOM Function #16
0x00800053highMETHOD_NEITHERFILE_DEVICE_CUSTOM Function #20
0x0080005FhighMETHOD_NEITHERFILE_DEVICE_CUSTOM Function #23
0x0080003BhighMETHOD_NEITHERFILE_DEVICE_CUSTOM Function #14
0x0080004BhighMETHOD_NEITHERFILE_DEVICE_CUSTOM Function #18
0x00800057highMETHOD_NEITHERFILE_DEVICE_CUSTOM Function #21
0x00800047highMETHOD_NEITHERFILE_DEVICE_CUSTOM Function #17
0x0080008FhighMETHOD_NEITHERFILE_DEVICE_CUSTOM Function #35
0x0080006BhighMETHOD_NEITHERFILE_DEVICE_CUSTOM Function #26
0x00800063highMETHOD_NEITHERFILE_DEVICE_CUSTOM Function #24
0x00800033highMETHOD_NEITHERFILE_DEVICE_CUSTOM Function #12

Showing 24 of 40 extracted control codes.

PE sections

Section layout and Shannon entropy. High entropy in a code section is a packing or encryption indicator.

SectionVirtual sizeRaw sizeEntropyFlags
.text0x1A8EA0x1B0006.25CODE, EXEC, READ
NONPAGED0x185640x190006.18CODE, EXEC, READ
fothk0x10000x10000.03CODE, EXEC, READ
.rdata0x19F680x1A0005.62IDATA, READ
.data0x08E80x10000.25IDATA, READ, WRITE
.pdata0x5D240x60005.79IDATA, READ
.idata0x48460x50004.71IDATA, READ
PAGE0x6B03E0x6C0006.32CODE, EXEC, READ
PAGED0x00740x10000.3CODE, EXEC, READ
INIT0x04180x10002.3CODE, EXEC, READ, DISCARD
GFIDS0x03900x10001.57IDATA, READ, DISCARD
.rsrc0xCB080xD0003.83IDATA, READ, DISCARD
.reloc0x33140x40004.94IDATA, READ, DISCARD

Exploit mitigations

Control Flow GuardEnabled
ASLREnabled
DEPEnabled
Integrity checkNot enforced
Mitigation score100 / 100

YARA rule matches (2)

RuleSeverityDetects
SUSP_PhysMemhighPhysical memory mapping
SUSP_CallbacksmediumKernel callback registration

MITRE ATT&CK techniques (19)

Techniques this driver could enable if loaded by an adversary.

IDTechniqueTactic
T1003OS Credential DumpingCredential Access
T1003.001OS Credential Dumping: LSASS MemoryCredential Access
T1006Direct Volume AccessDefense Evasion
T1014RootkitDefense Evasion
T1055.001Process Injection: DLL InjectionDefense Evasion
T1055.012Process HollowingDefense Evasion
T1068Exploitation for Privilege EscalationPrivilege Escalation
T1071Application Layer ProtocolCommand and Control
T1112Modify RegistryDefense Evasion
T1211Exploitation for Defense EvasionDefense Evasion
T1489Service StopImpact
T1543.003Windows ServicePersistence
T1547.001Registry Run KeysPersistence
T1553.002Subvert Trust Controls: Code SigningDefense Evasion
T1562.001Disable/Modify ToolsDefense Evasion
T1562.006Indicator BlockingDefense Evasion
T1564.001Hidden Files and DirectoriesDefense Evasion
T1569.002Service ExecutionExecution
T1652Device Driver DiscoveryDiscovery

Code-signing chain

SignerMicrosoft Windows
Signer organisationMicrosoft Corporation
IssuerMicrosoft Windows Production PCA 2011
Serial3300000519DADDAA8BDC44B292000000000519
Valid from2025-06-19 18:11 UTC
Valid until2026-06-17 18:11 UTC
Signature validityVerified

Symbolic execution

Engine angr, status static_approximation, 0 paths explored at a maximum depth of 0. Vulnerability classes reached: 0. Exploitable paths: 2.

Frequently asked questions about Vid.sys

Is Vid.sys safe?

Based on DriverShield static and dynamic analysis, Vid.sys shows some suspicious signals and warrants manual review. Its composite risk score is 58/100 (verdict: suspicious). Always validate findings independently before acting.

What is the risk score of Vid.sys?

Vid.sys has a DriverShield composite risk score of 58/100, placing it in the suspicious verdict band. SHA256: dbeda1711261688305c3f093b9aa677758fbbf3cf90be878783b498633ea888b.

What is Vid.sys?

Vid.sys is a Windows kernel-mode driver (.sys) analyzed by DriverShield for vulnerabilities, BYOVD abuse potential, and malware indicators. It is code-signed by Microsoft Windows.

Related: Other drivers signed by Microsoft Windows · What an IOCTL dispatch code is · How YARA matching feeds the score · BYOVD research index · full driver database · CVE library · code signing atlas


DriverShield © 2025-2026 · Terms · Privacy · Contact