# magicsword-io/LOLDrivers

Living Off The Land Drivers

Repository: https://github.com/magicsword-io/LOLDrivers
Canonical: https://ross.abutalabs.com/products/loldrivers
Homepage: https://www.loldrivers.io/
Language: YARA
License: Apache-2.0
License Family: permissive
Topics: drivers, malicious
Last push: 2026-08-12T19:52:02+00:00

## Health v2 (maintenance only)
Score: 65/100 (v2, computed 2026-09-03T02:20:16.233290+00:00)
- activity 97, release rhythm 8, longevity 92
- inputs: {"age_days": 1299, "days_push": 21, "days_rel": null, "gap_med": null, "n_releases_24m": 0}
- flags: none
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 1763, forks 223 (observed 2026-08-28T04:05:32.935560+00:00)

## What it is
LOLDrivers is a community-maintained curated dataset of vulnerable and malicious Windows drivers abused by adversaries (BYOVD attacks), with hashes, YARA rules, Sigma detections, and CSV/JSON APIs. It helps defenders detect and block known-bad drivers via SIEM queries, Sysmon configs, and hash blocklists.

## Use cases
- find malicious windows drivers in my environment
- block vulnerable drivers by hash
- detect BYOVD attacks in my SIEM
- get a feed of known malicious driver hashes
- check if a driver is on a blocklist
- build sigma rules for vulnerable drivers
- hunt for abused drivers with sysmon

## When to choose
- you need an up-to-date, community-maintained feed of vulnerable/malicious Windows driver hashes
- you want ready-made Sigma, YARA, ClamAV, or Sysmon detections for driver threats
- you need API access (CSV/JSON) to integrate driver intelligence into your tooling

## When to avoid
- you need general-purpose antivirus or endpoint protection rather than driver-specific intelligence
- you need detection for non-Windows platforms
- you need automated remediation rather than detection data

## Facets
- artifact type: dataset
- maturity: active
- function: security, vulnerability-scanning, monitoring, documentation
- domain: security, windows, developer-tools
- platform: windows, self-hosted
- tags: byovd, threat-intelligence, yara, sigma-rules, driver-blocklist, siem-detections, ioc-feed, web-server

## Member repositories
- magicsword-io/LOLDrivers (main) score 65

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:05:32.935560+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T03:26:46.980496+00:00, confidence not recorded.
  - readme: https://github.com/magicsword-io/LOLDrivers (fetched 2026-08-28T04:05:32.935560+00:00, sha 789752e11415)
  - homepage: https://www.loldrivers.io/ (fetched 2026-08-29T11:05:11.940379+00:00, sha 63c2bc690371)
  - site_page: https://www.loldrivers.io/about (fetched 2026-08-29T11:05:11.951737+00:00, sha 09fb399a8829)
  - site_page: https://loldrivers.io/about (fetched 2026-08-29T11:05:11.953566+00:00, sha 09fb399a8829)
- Data as of 2026-08-30T08:39:29.467469+00:00.
