0e272ccf-81e5-4612-95d2-365e7ded6eac
shield.sys 
Description
Horizon DataSys Shield drivers expose IOCTL functionality reported to provide arbitrary kernel read/write primitives.
- UUID: 0e272ccf-81e5-4612-95d2-365e7ded6eac
- Created: 2026-06-16
- Author: Michael Haag
- Acknowledgement: | DellaNotto
This download link contains the vulnerable driver!
Commands
sc.exe create shield binPath=C:\windows\temp\shield.sys type=kernel && sc.exe start shield
| Use Case | Privileges | Operating System |
|---|---|---|
| Load vulnerable signed disk filter drivers for kernel memory access | kernel | Windows 10, Windows 11 |
Detections
YARA 🏹
Expand
with header and size limitation
without header and size limitation
for renamed driver files
Resources
Known Vulnerable Samples
| Property | Value |
|---|---|
| Filename | shield.sys |
| Creation Timestamp | |
| MD5 | 97d6d9e9164354e40b5bcc828c6da3df |
| SHA1 | 4d0f2a70ce5cd0c868454de9afe9b4b09fcef5df |
| SHA256 | b11db76aeab05f29e8f5d51cdfe70898a46fbd50a1245ca1aed39de10aafd401 |
| Publisher | New Horizon Datasys Inc |
| Date | 07:33 PM 02/13/2026 |
| Company | Horizon Datasys, Inc. |
| Description | Shield disk filter driver |
| Product | Reboot Restore Standard |
| OriginalFilename | Shield.sys |
Imports
Expand
Imported Functions
Expand
Exported Functions
Expand
Sections
Expand
Signature
Expand
| Property | Value |
|---|---|
| Filename | shield-async.sys |
| Creation Timestamp | |
| MD5 | 77e6a2b6883fb823d95d2d7659fedb1c |
| SHA1 | fde65f0c98d0ca07144febb877d658f0287d2c12 |
| SHA256 | da3315363989b564a1b8b690bddfeb3bd81c1690a3da5813ca0c46a715fe94b0 |
| Publisher | New Horizon Datasys Inc |
| Date | 07:33 PM 02/13/2026 |
| Company | Horizon Datasys, Inc. |
| Description | Shield async disk filter driver |
| Product | Reboot Restore Standard |
| OriginalFilename | Shield-async.sys |
Imports
Expand
Imported Functions
Expand
Exported Functions
Expand
Sections
Expand
Signature
Expand
| Property | Value |
|---|---|
| Filename | shieldwp.sys |
| Creation Timestamp | |
| MD5 | e2bfb13653b0569e4c3ddbde10f89493 |
| SHA1 | 46ac52bc089575a393e6fc9adec6b63f63190e1c |
| SHA256 | b1547490f3040b1e3668ee195adbf2d312024809915d01a71ed75fae72971a9d |
| Publisher | New Horizon Datasys Inc |
| Date | 07:34 PM 02/13/2026 |
| Company | Horizon Datasys, Inc. |
| Description | Shield disk filter driver |
| Product | Reboot Restore Standard |
| OriginalFilename | Shield.sys |
Imports
Expand
Imported Functions
Expand
Exported Functions
Expand
Sections
Expand
Signature
Expand
last_updated: 2026-06-16
