← Back to driver explorer
Driver intelligenceVulnerableVerified
vsdatant.sys
Check Point ZoneAlarm driver (vsdatant.sys) abused in BYOVD attacks to gain kernel privileges and bypass protections such as Memory Integrity.
Known samples 1
0 recorded TRUE · 0 recorded FALSE · 1 unknown for loading despite HVCI. Results apply to individual samples.
vsdatant.sysSample 1 · HVCI unknown
- MD5
190fe0ce4d43ad8eed97aaa68827e2c6- SHA1
f16d24ed98bcc35ecae902474abfc4820db541da- SHA256
1c43f33573a0815c5edc5e18ba1038afdd11f55a7cd8b08ba59b8f7357117e4c- Imphash
898c18bb22258c225c07e8476efdf79e- Authentihash MD5
d4534a5aed4e8fadbd30af524a956c38- Authentihash SHA1
a51490ec6c31de4fcdd7b5f053a1d9b58971308e- Authentihash SHA256
9b2bb2385b742eef4f614cd6b2e714444f3e983e8643e673c6f3e917618260d4- Machine
- AMD64
- Version
- Not recorded
- Publisher
- Check Point, LTD
Recorded command
sc.exe create vsdatant binPath=C:\Windows\Temp\vsdatant.sys type=kernel && sc.exe start vsdatantBYOVD (kernel) privilege escalation / defense evasion · Privileges: kernel · OS: Windows 10
Research & references
Acknowledgement: Venak Security

