BYOVD: Cyber Threats, EDR/XDR Disablement, and the Power of Air-Gap Backups with Instant Recovery
- Oleg Vusiker
- Nov 12, 2023
- 2 min read
Updated: Nov 19, 2023

In the ever-evolving landscape of cyber threats, a new challenge has emerged known as "Bring Your Own Vulnerable Driver" (BYOVD). This cyber-attack technique, employed by both cybercriminal groups and nation-state actors, exploits vulnerabilities in legitimate, signed drivers – components crucial to the functionality of security products like Antivirus (AV), Extended Detection and Response (XDR), and Endpoint Detection and Response (EDR).
BYOVD allows threat actors to successfully exploit systems, explicitly using legitimate signed drivers to turn off essential components of AV, XDR, and EDR, effectively neutralizing traditional defense solutions.
Two recent high-profile BYOVD attacks underscore the severity of this threat. The BlackByte ransomware gang, as revealed by Sophos researchers, demonstrated the sophistication of BYOVD by exploiting a vulnerability in the Micro-Star MSI Afterburner utility. This attack leveraged a known vulnerability in the legitimate RTCore64.sys driver, turning off crucial components relied upon by security products. Concurrently, the Lazarus APT group utilized BYOVD to deploy a Windows rootkit, exploiting a Dell firmware driver vulnerability (CVE-2021-21551) in targeted attacks against aerospace industry employees and journalists during the autumn of 2021.
The reach of BYOVD extends beyond nation-state actors, with cybercrime groups such as RobbinHood and AvosLocker incorporating this technique. These groups exploited vulnerabilities (e.g., CVE-2018-19320) in drivers to bypass security solutions and compromise target systems. Other instances involve threat actors abusing a vulnerable anti-cheat driver in the Genshin Impact video game, AvosLocker disabling essential components, and the Candiru surveillance spyware leveraging BYOVD to elevate privileges through zero-day exploits.
As the threat landscape evolves, traditional security solutions like AV, XDR, and EDR face limitations against the sophistication of BYOVD. Relying solely on these tools proves insufficient. The cybersecurity paradigm must shift towards prioritizing air-gapped backups with instant recovery, mainly when attackers successfully use legitimate signed drivers to turn off critical AV, XDR, and EDR components. This approach ensures the security of critical data, even in the event of BYOVD attacks.

In the dynamic field of cybersecurity, Salvador Technologies provides innovative solutions with a recovery capability that sets a new standard for operational resilience.
Our Security Failover Technology ensures a quick 30-second recovery from BYOVD attacks and other sophisticated exploits. With air-gapped data protection, we strengthen cyber defense beyond traditional detection measures. As BYOVD threats grow, we empower organizations to navigate the challenges of the digital era with innovative recovery capability.
The article by Salvador Technologies explores the rising threat of BYOVD (Bring Your Own Vulnerable Driver) attacks, which allow hackers to disable advanced security tools like EDR and XDR by exploiting legitimate but flawed drivers. Highlighting real-world cases such as the BlackByte ransomware and Lazarus APT group, the post emphasizes the urgent need for resilient cybersecurity strategies. Salvador promotes air-gapped backups with instant recovery—capable of restoring systems in just 30 seconds—as a critical defense against such sophisticated threats. For students seeking Mechanical Engineering Assignment Help, this underscores the importance of integrating robust backup and recovery solutions into engineering systems to ensure data integrity and operational continuity in the face of modern cyber risks.
Struggling to keep up with your assignment tasks? Get expert assignment help from AssignmentHelpPro and take the stress out of your studies. Our team of qualified professionals specializes in delivering top-notch, plagiarism-free assignments tailored to your specific requirements and university standards. Whether it’s an essay, dissertation, case study, or research paper, we offer comprehensive support across a wide range of subjects. With timely delivery, 24/7 customer support, and affordable pricing, AssignmentHelpPro is the go-to platform for students seeking reliable assignment help. Let us handle the workload while you focus on achieving academic success.
You are the best of the best. Salute!
durban poison
These rash guards help regulate body temperature and wick away sweat — so you stay cool, dry, and focused from start to finish. Shoyoroll Rash Guards
Navigating statistical software demands precision, especially when dealing with econometrics, regression analysis, and data interpretation. For students aiming to excel, a proficient Stata Assignment Helper becomes indispensable. Assignment Help Pro United States offers tailored guidance, ensuring students decode complex datasets, apply statistical models accurately, and present empirical findings with academic integrity.
By integrating methodological clarity and applied expertise, Assignment Help Pro United States empowers learners to master Stata’s advanced functionalities. Their scholarly approach not only strengthens technical proficiency but also enhances students' analytical capabilities, preparing them for both academic excellence and data-driven decision-making in professional contexts.