Analysis of ArgusMonitor.sys: clean verdict, risk score 29/100. 0 YARA matches, 0/75 multi-engine detections. SHA256 dd61f36ee9971c6b. Kernel imports, IOCTL codes, MITRE ATT&CK, and code-signing details.
DriverShield analyzed the Windows kernel driver ArgusMonitor.sys and assigned a verdict of Clean with a composite risk score of 29/100, indicating no notable risk signals (0-29 band).
| Verdict | Clean (29/100) |
| YARA matches | 0 |
| Multi-engine detections | 0 / 75 |
| File size | 83144 bytes |
| Code-signing signer | Microsoft Windows Hardware Compatibility Publisher |
| Analyzed | 2026-09-28 |
| SHA256 | dd61f36ee9971c6b8ad7a245d1f43fe0a2cf8502368a965bbf64c2e621cd4855 |
| SHA1 | 280128481db5856b3dc55313935ff18445751875 |
| MD5 | 35d625433d19c582396dba58443bbfc9 |
Version resource data embedded in the ArgusMonitor.sys PE header, as extracted by the analysis engine.
| File description | Argus Monitor Hardware Access Driver |
|---|---|
| Product | Argus Monitor Driver |
| Company | Argotronic eGbR |
| Original filename | ArgusMonitor.sys |
| Internal name | ArgusMonitor.sys |
| File version | 4.04.0 |
| Copyright | Copyright (C) 2008-2026 Argotronic eGbR. All rights reserved. |
Each component is scored 0-100 and then weighted into the composite. See the analysis methodology for the exact formula.
| Component | Sub-score |
|---|---|
| Multi-engine consensus | 0 / 100 |
| YARA signature matches | 0 / 100 |
| Dangerous kernel imports | 100 / 100 |
| IOCTL dispatch surface | 87 / 100 |
| Known-vulnerable corpus | 0 / 100 |
| Code-signing state | 0 / 100 |
| Packing and entropy | 0 / 100 |
| Dynamic behaviour | 0 / 100 |
| CVE cross-reference | 0 / 100 |
Kernel-mode APIs resolved from the Import Address Table of ArgusMonitor.sys, ranked by exploitation relevance.
| API | Risk | Why it matters |
|---|---|---|
| HalSetBusDataByOffset | high | Potentially dangerous - could be used for privilege escalation or security bypass |
| HalGetBusDataByOffset | high | Potentially dangerous - could be used for privilege escalation or security bypass |
| MmGetSystemRoutineAddress | high | Potentially dangerous - could be used for privilege escalation or security bypass |
| ObOpenObjectByPointer | medium | Moderate risk - system modification capability |
| ZwWriteFile | medium | Moderate risk - system modification capability |
| ZwSetValueKey | medium | Moderate risk - system modification capability |
| IoGetDeviceObjectPointer | medium | Moderate risk - system modification capability |
| ZwSetInformationFile | medium | Moderate risk - system modification capability |
| MmUnmapIoSpace | medium | Moderate risk - system modification capability |
| ZwCreateKey | medium | Moderate risk - system modification capability |
| IofCompleteRequest | low | Standard kernel API - generally benign |
| IoCreateDeviceSecure | low | Standard kernel API - generally benign |
| IoDeleteDevice | low | Standard kernel API - generally benign |
| IoCreateDevice | low | Standard kernel API - generally benign |
| ZwQueryValueKey | low | Standard kernel API - generally benign |
| ZwOpenFile | low | Standard kernel API - generally benign |
| KeDelayExecutionThread | low | Standard kernel API - generally benign |
| KeSetEvent | low | Standard kernel API - generally benign |
| ZwClose | low | Standard kernel API - generally benign |
| KeInitializeEvent | low | Standard kernel API - generally benign |
| ZwReadFile | low | Standard kernel API - generally benign |
| ExAllocatePool2 | low | Standard kernel API - generally benign |
| IoCreateSymbolicLink | low | Standard kernel API - generally benign |
| KeWaitForSingleObject | low | Standard kernel API - generally benign |
| ExAllocatePoolWithTag | low | Standard kernel API - generally benign |
| RtlInitUnicodeString | low | Standard kernel API - generally benign |
| ZwCreateFile | low | Standard kernel API - generally benign |
| IoBuildDeviceIoControlRequest | low | Standard kernel API - generally benign |
Showing the 28 highest-relevance imports of 31 resolved.
Control codes reachable through the driver dispatch routine. Codes tied to published exploit code are flagged, since they are the primary Bring Your Own Vulnerable Driver (BYOVD) entry points.
| Code | Severity | Transfer | Description |
|---|---|---|---|
| 0x0022B807 | high | METHOD_NEITHER | FILE_DEVICE_UNKNOWN Function #3585 |
| 0x00220117 | high | METHOD_NEITHER | FILE_DEVICE_UNKNOWN Function #69 |
| 0x002200F0 | medium | METHOD_BUFFERED | FILE_DEVICE_UNKNOWN Function #60 |
| 0x9C4020FC | medium | METHOD_BUFFERED | CUSTOM_LENOVO Function #2111 |
| 0x9C402498 | medium | METHOD_BUFFERED | CUSTOM_LENOVO Function #2342 |
| 0x9C402A00 | medium | METHOD_BUFFERED | CUSTOM_LENOVO Function #2688 |
| 0x9C402D9C | medium | METHOD_BUFFERED | CUSTOM_LENOVO Function #2919 |
| 0x9C4030F8 | medium | METHOD_BUFFERED | CUSTOM_LENOVO Function #3134 |
| 0x9C4034D8 | medium | METHOD_BUFFERED | CUSTOM_LENOVO Function #3382 |
| 0x9C403C30 | medium | METHOD_BUFFERED | CUSTOM_LENOVO Function #3852 |
| 0x9C403D8C | medium | METHOD_BUFFERED | CUSTOM_LENOVO Function #3939 |
| 0x0080FE81 | medium | METHOD_IN_DIRECT | FILE_DEVICE_CUSTOM Function #4000 |
| 0x9C4036E4 | medium | METHOD_BUFFERED | CUSTOM_LENOVO Function #3513 |
| 0x9C4039FC | medium | METHOD_BUFFERED | CUSTOM_LENOVO Function #3711 |
| 0x008024BC | medium | METHOD_BUFFERED | FILE_DEVICE_CUSTOM Function #2351 |
| 0x0080BC41 | medium | METHOD_IN_DIRECT | FILE_DEVICE_CUSTOM Function #3856 |
| 0x0080EC81 | medium | METHOD_IN_DIRECT | FILE_DEVICE_CUSTOM Function #2848 |
| 0x00802D00 | medium | METHOD_BUFFERED | FILE_DEVICE_CUSTOM Function #2880 |
| 0x0080BA41 | medium | METHOD_IN_DIRECT | FILE_DEVICE_CUSTOM Function #3728 |
| 0x0080BF41 | medium | METHOD_IN_DIRECT | FILE_DEVICE_CUSTOM Function #4048 |
| 0x003433E8 | medium | METHOD_BUFFERED | FILE_DEVICE_DISK Function #3322 |
| 0x0034FFE8 | medium | METHOD_BUFFERED | FILE_DEVICE_DISK Function #4090 |
| 0x00341880 | medium | METHOD_BUFFERED | FILE_DEVICE_DISK Function #1568 |
| 0x00340030 | medium | METHOD_BUFFERED | FILE_DEVICE_DISK Function #12 |
Showing 24 of 29 extracted control codes.
Section layout and Shannon entropy. High entropy in a code section is a packing or encryption indicator.
| Section | Virtual size | Raw size | Entropy | Flags |
|---|---|---|---|---|
| .text | 0xB457 | 0xB600 | 6.4 | CODE, EXEC, READ |
| .rdata | 0x17AC | 0x1800 | 5.18 | IDATA, READ |
| .data | 0x14A0 | 0x0C00 | 5.13 | IDATA, READ, WRITE |
| .pdata | 0x06A8 | 0x0800 | 4.09 | IDATA, READ |
| PAGE | 0x1C4F | 0x1E00 | 6.08 | CODE, EXEC, READ |
| INIT | 0x0FCE | 0x1000 | 5.65 | CODE, EXEC, READ, DISCARD |
| .rsrc | 0x0458 | 0x0600 | 2.73 | IDATA, READ, DISCARD |
| .reloc | 0x003C | 0x0200 | 0.81 | IDATA, READ, DISCARD |
| Control Flow Guard | Enabled |
|---|---|
| ASLR | Enabled |
| DEP | Enabled |
| Integrity check | Not enforced |
| Mitigation score | 100 / 100 |
Techniques this driver could enable if loaded by an adversary.
| ID | Technique | Tactic |
|---|---|---|
| T1003.001 | OS Credential Dumping: LSASS Memory | Credential Access |
| T1014 | Rootkit | Defense Evasion |
| T1055.012 | Process Hollowing | Defense Evasion |
| T1068 | Exploitation for Privilege Escalation | Privilege Escalation |
| T1112 | Modify Registry | Defense Evasion |
| T1211 | Exploitation for Defense Evasion | Defense Evasion |
| T1542.001 | Pre-OS Boot: System Firmware | Persistence |
| T1543.003 | Windows Service | Persistence |
| T1547.001 | Registry Run Keys | Persistence |
| T1553.002 | Subvert Trust Controls: Code Signing | Defense Evasion |
| T1569.002 | Service Execution | Execution |
| T1601 | Modify System Image | Defense Evasion |
| T1652 | Device Driver Discovery | Discovery |
| Signer | Microsoft Windows Hardware Compatibility Publisher |
|---|---|
| Signer organisation | Microsoft Corporation |
| Issuer | Microsoft Windows Third Party Component CA 2014 |
| Serial | 33000000849686AEDFB4B66376000000000084 |
| Valid from | 2026-05-13 18:17 UTC |
| Valid until | 2027-05-11 18:17 UTC |
| Signature validity | Verified |
Engine angr, status static_approximation, 0 paths explored at a maximum depth of 0. Vulnerability classes reached: 0. Exploitable paths: 1.
Based on DriverShield static and dynamic analysis, ArgusMonitor.sys is assessed as clean, with no notable risk signals. Its composite risk score is 29/100 (verdict: clean). Always validate findings independently before acting.
ArgusMonitor.sys has a DriverShield composite risk score of 29/100, placing it in the clean verdict band. SHA256: dd61f36ee9971c6b8ad7a245d1f43fe0a2cf8502368a965bbf64c2e621cd4855.
ArgusMonitor.sys is a Windows kernel-mode driver (.sys) analyzed by DriverShield for vulnerabilities, BYOVD abuse potential, and malware indicators. It is code-signed by Microsoft Windows Hardware Compatibility Publisher.
Related: Other drivers signed by Microsoft Windows Hardware Compatibility Publisher · What an IOCTL dispatch code is · BYOVD research index · full driver database · CVE library · code signing atlas