03-09-2026
Bring Your Own Trusted Caller (BYOTC): A New Way to Exploit Vulnerable Windows Drivers (Part 1)
https://xusheng.dev/posts/byotc/main/
Report completeness: Low
Threats:
Byovd_technique
Toctou_vuln
Victims:
Microsoft defender, Malwarebytes, System informer
TTPs:
Tactics: 1
Technics: 0
ChatGPT TTPs:
do not use without manual checkT1055, T1068, T1562.001
IOCs:
File: 6
Hash: 1
Path: 4
Soft:
Microsoft Defender, macOS
Algorithms:
sha512, sha256
Win API:
ZwTerminateProcess, PsGetProcessProtection, PsProtectedSignerWinTcb, PsProtectedSignerWinSystem
Win Services:
MsMpEng, exe
Platforms:
apple
Links:
https://github.com/winsiderss/systeminformer/blob/553d309edb07934bda9387cff29a82ca1714acbb/kphlib/include/kphapi.h#L20-L76have more...
https://github.com/winsiderss/systeminformer/blob/553d309edb07934bda9387cff29a82ca1714acbb/KSystemInformer/verify.c#L405-L614https://github.com/winsiderss/systeminformer/blob/553d309edb07934bda9387cff29a82ca1714acbb/KSystemInformer/cid\_tracking.c#L2270-L2354