skilly. Buy ad slot
All skills
Community / AGENT SKILL

analyzing-windows-driver-malware

meltedinhex/analyst-ai-pack
0 installs 22 GitHub stars
0

Analyzes malicious and vulnerable Windows kernel drivers (.sys) by parsing the PE for the native subsystem, identifying DriverEntry/IRP dispatch and IOCTL handlers, and flagging BYOVD and kernel-callback abuse. Activates for requests to analyze a Windows driver, examine a .sys sample, or assess a BYOVD/kernel driver threat.

BEFORE YOU INSTALL

Understand the trade-offs.

SECURITY REVIEW

Not yet assessed

Review the original instructions and requested permissions before installing.

No security review is available for this catalog entry yet.

SKILL QUALITY

Not yet assessed

How clearly the skill guides your agent, how complete its workflow is, and how you can check the outcome.

No quality assessment is available for this catalog entry yet.

The full skill.

Original instructions from the publisher’s SKILL.md

# Analyzing Windows Driver Malware

## When to Use

- You have a `.sys` kernel driver (malicious rootkit driver or a vulnerable driver used for BYOVD)
  and need to identify its entry, IRP/IOCTL handlers, and dangerous kernel operations.
- You are assessing privilege-escalation or kernel-stealth risk.

**Do not use** this by loading the driver — analyze it statically. Loading kernel code is
dangerous and is the threat itself.

## Prerequisites

- The driver `.sys` (read inertly).

## Safety & Handling

- Read bytes statically; never install/load the driver. Note its signing status for BYOVD context.

## Workflow

### Step 1: Confirm it is a kernel driver

```bash
python scripts/analyst.py inspect driver.sys
```

Verifies the PE native subsystem (1), kernel imports (`ntoskrnl.exe`, `hal.dll`), and reports
imported kernel APIs.

### Step 2: Identify dispatch and dangerous primitives

Flag IRP/IOCTL handling (`IoCreateDevice`, `IoCreateSymbolicLink`, `IRP_MJ_DEVICE_CONTROL`),
arbitrary read/write primitives (`MmMapIoSpace`, `ZwMapViewOfSection`, `MmCopyMemory`), and
callback registration (`PsSetCreateProcessNotifyRoutine`, `ObRegisterCallbacks`).

### Step 3: Assess BYOVD/stealth potential

Map exposed IOCTLs to capabilities (physical memory access, process kill, token theft) that BYOVD
abuse relies on.

### Step 4: Document

Record the driver's handlers, dangerous primitives, signing status, and risk.

## Validation

- Native subsystem and kernel imports confirm a driver.
- Dispatch/IOCTL and dangerous-primitive imports are reported with evidence.
- Capabilities are tied to concrete imported APIs.

## Pitfalls

- Legitimate vendor drivers that are nonetheless exploitable (BYOVD) — context matters.
- Drivers resolving APIs dynamically, hiding imports.
- Confusing user-mode helper components with the kernel driver itself.

## References

- See [`references/api-reference.md`](references/api-reference.md) for the inspector.
- WDK and ATT&CK T1068 references (linked in frontmatter).