percsas3i.sys - Clean (9/100) - DriverShield Analysis

Analysis of percsas3i.sys: clean verdict, risk score 9/100. 0 YARA matches. SHA256 92017ecb36eaa35a. Kernel imports, IOCTL codes, MITRE ATT&CK, and code-signing details.

percsas3i.sys - Analysis Report

DriverShield analyzed the Windows kernel driver percsas3i.sys and assigned a verdict of Clean with a composite risk score of 9/100, indicating no notable risk signals (0-29 band).

VerdictClean (9/100)
YARA matches0
File size68408 bytes
Code-signing signerMicrosoft Windows
Analyzed2026-03-22
SHA25692017ecb36eaa35ac454e890734915a658eb898c95970531d43c19461be6562b
SHA1ac8f33dc88bfa7bd3f3af773901eb96c9194cf02
MD51c6720616ff300235509d5efbb2cae20

Driver identity

Version resource data embedded in the percsas3i.sys PE header, as extracted by the analysis engine.

File descriptionMEGASAS RAID Controller Driver for Windows
ProductMEGASAS RAID Controller Driver for Windows
CompanyAvago Technologies
Original filenamePercSas3.sys
Internal namePercSas3.sys
File version6.604.06.00
CopyrightCopyright © Avago Technologies2013

How the 9/100 score breaks down

Each component is scored 0-100 and then weighted into the composite. See the analysis methodology for the exact formula.

ComponentSub-score
Multi-engine consensus0 / 100
YARA signature matches0 / 100
Dangerous kernel imports0 / 100
IOCTL dispatch surface42 / 100
Known-vulnerable corpus0 / 100
Code-signing state80 / 100
Packing and entropy0 / 100
Dynamic behaviour0 / 100
CVE cross-reference0 / 100

IOCTL dispatch codes (14)

Control codes reachable through the driver dispatch routine. Codes tied to published exploit code are flagged, since they are the primary Bring Your Own Vulnerable Driver (BYOVD) entry points.

CodeSeverityTransferDescription
0x00808B8BhighMETHOD_NEITHERFILE_DEVICE_CUSTOM Function #738
0x0080898BhighMETHOD_NEITHERFILE_DEVICE_CUSTOM Function #610
0x0080818BhighMETHOD_NEITHERFILE_DEVICE_CUSTOM Function #98
0x0080918BhighMETHOD_NEITHERFILE_DEVICE_CUSTOM Function #1122
0x0080838BhighMETHOD_NEITHERFILE_DEVICE_CUSTOM Function #226
0x0080878BhighMETHOD_NEITHERFILE_DEVICE_CUSTOM Function #482
0x0080A28BhighMETHOD_NEITHERFILE_DEVICE_CUSTOM Function #2210
0x002200F0mediumMETHOD_BUFFEREDFILE_DEVICE_UNKNOWN Function #60
0x0080248CmediumMETHOD_BUFFEREDFILE_DEVICE_CUSTOM Function #2339
0x00802484mediumMETHOD_BUFFEREDFILE_DEVICE_CUSTOM Function #2337
0x0022FBE8mediumMETHOD_BUFFEREDFILE_DEVICE_UNKNOWN Function #3834
0x00808789mediumMETHOD_IN_DIRECTFILE_DEVICE_CUSTOM Function #482
0x008024B4mediumMETHOD_BUFFEREDFILE_DEVICE_CUSTOM Function #2349
0x0034037CmediumMETHOD_BUFFEREDFILE_DEVICE_DISK Function #223

PE sections

Section layout and Shannon entropy. High entropy in a code section is a packing or encryption indicator.

SectionVirtual sizeRaw sizeEntropyFlags
.text0xB0EA0xB2006.24CODE, EXEC, READ
.rdata0x113C0x12004.74IDATA, READ
.data0x06350x08002.55IDATA, READ, WRITE
.pdata0x08580x0A003.98IDATA, READ
.gfids0x00040x02000.02IDATA, READ
INIT0x03640x04004.4CODE, EXEC, READ, DISCARD
.rsrc0x07880x08005.27IDATA, READ, DISCARD
.reloc0x00E40x02002.83IDATA, READ, DISCARD

Exploit mitigations

Control Flow GuardNot enabled
ASLREnabled
DEPEnabled
Integrity checkNot enforced
Mitigation score55 / 100

MITRE ATT&CK techniques (3)

Techniques this driver could enable if loaded by an adversary.

IDTechniqueTactic
T1071Application Layer ProtocolCommand and Control
T1543.003Windows ServicePersistence
T1652Device Driver DiscoveryDiscovery

Code-signing chain

SignerMicrosoft Windows
Signer organisationMicrosoft Corporation
IssuerMicrosoft Windows Production PCA 2011
Serial330000023241FB59996DCC4DFF000000000232
Valid from2019-05-02 21:24 UTC
Valid until2020-05-02 21:24 UTC (expired)
Signature validityNot verified

Symbolic execution

Engine angr, status no_findings, 0 paths explored at a maximum depth of 0. Vulnerability classes reached: 0. Exploitable paths: 0.

Frequently asked questions about percsas3i.sys

Is percsas3i.sys safe?

Based on DriverShield static and dynamic analysis, percsas3i.sys is assessed as clean, with no notable risk signals. Its composite risk score is 9/100 (verdict: clean). Always validate findings independently before acting.

What is the risk score of percsas3i.sys?

percsas3i.sys has a DriverShield composite risk score of 9/100, placing it in the clean verdict band. SHA256: 92017ecb36eaa35ac454e890734915a658eb898c95970531d43c19461be6562b.

What is percsas3i.sys?

percsas3i.sys is a Windows kernel-mode driver (.sys) analyzed by DriverShield for vulnerabilities, BYOVD abuse potential, and malware indicators. It is code-signed by Microsoft Windows.

Related: Other drivers signed by Microsoft Windows · What an IOCTL dispatch code is · BYOVD research index · full driver database · CVE library · code signing atlas


DriverShield © 2025-2026 · Terms · Privacy · Contact