szkg64.sys
The StopZilla driver is a forgotten but still exploitable vulnerable driver that allows arbitrary kernel memory writes via unvalidated IOCTLs (0x80002063 and 0x8000206F). Attackers can leverage it to escalate privileges, disable LSASS PPL protection, and even modify PreviousMode in _KTHREAD to execute user-mode code as kernel-mode, effectively bypassing security checks. Despite its risks, it remains unblocked by Microsoft’s Driver Block List and many AV/EDR solutions. This driver highlights the persistent threat of forgotten vulnerable drivers still exploitable in modern Windows environments.
Known samples 1
0 recorded TRUE · 0 recorded FALSE · 1 unknown for loading despite HVCI. Results apply to individual samples.
szkg64.sysSample 1 · HVCI unknown
- MD5
8598e4a12eaa945b35365dd2750b9777- SHA1
d7698828cdc3c96cc17fe2d4ff6d93bb0cd355d8- SHA256
6bc0e1c104fac4a8caa4237c7ae181ca11a043a3ee26426aeb7a90dc40281fad- Imphash
f5a9e7716a1b8e1d5f64dfacca5283d0- Authentihash MD5
392ed92d6a91fa7cd318e2846ce07490- Authentihash SHA1
c516d0e96129086f6096e1e38ae90ed4da736ccb- Authentihash SHA256
95ca14e045618fb38834d17c5cc176162a29d846c1463b840c9129fb9af47c68- Machine
- AMD64
- Version
- 3.0.24
- Publisher
- iS3 Inc.
Recorded command
sc.exe create szkg64.sys binPath=C:\windows\temp\szkg64.sys type=kernel && sc.exe start szkg64.sysElevate privileges · Privileges: kernel · OS: Windows 11

