
Our research project introduces a sandbox extension aimed at monitoring and analyzing BYOVD (Bring Your Own Vulnerable Driver) behaviors within a controlled environment, enabling the detection of anomalies that may indicate exploitation. As part of this work, we provide several key artifacts: the kernelmon plugin, which extends the sandbox with kernel-level tracing capabilities; the configuration files required to run the plugin; an analysis application that correlates the collected events; the sets of analyzed drivers' hashes; the corresponding sets of sample hashes obtained from those drivers; the results from our experiments and analysis. The "Unveiling BYOVD Threats: Malware's Use and Abuse of Kernel Drivers" article can be found at https://dx.doi.org/10.14722/ndss.2026.231491
| citations This is an alternative to the "Influence" indicator, which also reflects the overall/total impact of an article in the research community at large, based on the underlying citation network (diachronically). | 0 | |
| popularity This indicator reflects the "current" impact/attention (the "hype") of an article in the research community at large, based on the underlying citation network. | Average | |
| influence This indicator reflects the overall/total impact of an article in the research community at large, based on the underlying citation network (diachronically). | Average | |
| impulse This indicator reflects the initial momentum of an article directly after its publication, based on the underlying citation network. | Average |
