DriverShield - Kernel Driver Vulnerability & Malware Analysis
Analyze Windows .sys kernel drivers for vulnerabilities, rootkit behavior, BYOVD attack patterns, and malware. YARA matching, MITRE ATT&CK mapping, and Sigma rule generation.
Analyze a Windows Kernel Driver
DriverShield combines static and dynamic analysis to inspect Windows .sys kernel drivers for vulnerabilities, BYOVD (Bring Your Own Vulnerable Driver) abuse patterns, rootkit behaviour, and malware indicators. The platform is free to use and produces a 0-100 risk score with a verdict in the clean / suspicious / vulnerable / malicious band.
Capabilities
- PE structure and section entropy analysis
- Dangerous kernel API (Zw/Nt) classification
- IOCTL dispatch code extraction with known-exploit lookup
- Authenticode certificate chain verification
- YARA matching with 12 built-in rules plus 500+ synced signatures
- Multi-engine consensus and hash reputation
- Symbolic execution for vulnerability surface mapping
- MITRE ATT&CK technique mapping and Sigma rule synthesis
- Known-vulnerable driver cross-reference
Read the analysis methodology for the full pipeline, browse the CVE library for documented kernel-driver vulnerabilities, or explore the signer atlas to see drivers grouped by their code-signing certificates.
DriverShield © 2025-2026 · Terms · Privacy · Contact