Tag
high
advisory
Threat Actors Disabling AV and EDR Solutions
2 rules 2 TTPsThreat actors are actively disabling antivirus and EDR solutions through abusing Windows Firewall rules, uninstalling agents, and exploiting vulnerable drivers (BYOVD) to establish persistence, move laterally, and deploy ransomware undetected.
Defender Antivirus +2
defense-evasion
privilege-escalation
byovd
2r
2t
high
advisory
TVicPort64.sys Arbitrary Physical Memory Mapping LPE
2 rules 1 TTPThe TVicPort64.sys driver, signed by EnTech Taiwan in 2006, is vulnerable to arbitrary physical memory mapping, enabling local privilege escalation on Windows systems.
TVicPort64.sys
lpe
byovd
privilege-escalation
signed-driver
2r
1t