
Can vulnerable drivers still kill your EDR in 2026? Spoiler: yes. 🧵 New Weekly Purple Team drops today — BYOVD using CVE-2023-52271 (wsftprm.sys), a signed driver STILL not on Microsoft's blocklist. 🔴 Attack: malicious IOCTL → ZwTerminateProcess at kernel level → EDR gone 🔵 Detect: Event ID 6, 4697, 7045, WDAC enforcement Video 👇 https://youtu.be/q6VMly9Bs5s #BYOVD #PurpleTeam #DetectionEngineering #ThreatHunting
Post summary
The post shares a video demonstrating how CVE‑2023‑52271 can be leveraged by sending malicious IOCTLs to ZwTerminateProcess, enabling an attacker to terminate EDR processes on a target system.


