Fumo Loader - All in one kernel-based DLL injector
-
Updated
Jul 8, 2026 - C++
Fumo Loader - All in one kernel-based DLL injector
Kernel-mode process terminator using a signed BYOVD driver. Works on all Windows 10/11. No offsets, no PDB. Rust.
Advanced PoC & Research for CVE-2026-0828 (Safetica) and CVE-2025-7771 (ThrottleStop). Analysis of BYOVD (Bring Your Own Vulnerable Driver) TTPs for Ring 0 process termination and physical memory R/W. Researching EDR-Killer patterns, PPL bypasses, and kernel-mode primitives used by MedusaLocker and other threat actors.
Windows BYOVD research on DCRCVDrv.sys and Alinubx.sys, reverse engineering their kernel primitives, IOCTL surfaces, and detection opportunities.
Vulnerable Drivers
A BYOVD PoC exploitation Alinubx.sys to terminate Windows processes.
Scans for popular vulnerable drivers that can be exploited to map unsigned driver to kernel space.
LOLDrivers YARA Rule Generator
Windows process memory mirroring through the signed vulnerable Panda driver PSMEMDriver (BYOVD): read/write via mapped physical pages, no OpenProcess/ReadProcessMemory.
Vanguard Bypass Pro is a cutting-edge utility designed to enhance system compatibility and streamline software performance. It offers advanced environment management for a smoother and more flexible experience.
A simple writeup of an driver found in the LOLDrivers repository.
POC for vulnerable driver DrvHWX64.sys (Totally unique EDR driver exposing various functions via IOCTL)
To associate your repository with the vulnerable-driver topic, visit your repo's landing page and select "manage topics."