DeepZero: Open-source hunting for vulnerable Windows drivers

Source: Help Net Security

Author: Mirko Zorz

URL: https://www.helpnetsecurity.com/2026/09/16/vulnerable-windows-drivers-deepzero-open-source/

https://www.helpnetsecurity.com/2026/09/16/vulnerable-windows-drivers-deepzero-open-source/

ONE SENTENCE SUMMARY:

DeepZero automates finding exploitable Windows kernel drivers using YAML pipelines, static analysis, filtering, and LLM exploitability assessment.

MAIN POINTS:

  1. DeepZero scans folders of Windows driver binaries to locate exploit candidates automatically.
  2. Project is open-source, written in Python 3.11+, with YAML-defined pipelines.
  3. Maintainer reports multiple verified vulnerabilities found in Snappy Driver Installer driver corpus.
  4. Included pipeline focuses on BYOVD attacks using signed but vulnerable kernel drivers.
  5. Stage one parses PE headers to extract metadata and initial driver characteristics.
  6. Stage two retains only kernel-mode drivers exposing reachable IOCTL interfaces.
  7. Stage three removes drivers already listed on loldrivers.io to avoid known cases.
  8. Ghidra headless decompilation and Semgrep rules analyze recovered/exported C-like output.
  9. A reduction step selects top candidates before sending artifacts to a language model.
  10. Hardware-dependent device creation can block confirmation without correct devices enumerated.

TAKEAWAYS:

  1. Layered filtering ensures the LLM reviews only high-signal, novel driver candidates.
  2. BYOVD remains practical because signed drivers can still contain exploitable flaws.
  3. Static reports may miss issues when device objects are created only via plug-and-play callbacks.
  4. Tracking IoCreateDevice location helps distinguish universally reachable drivers from hardware-gated ones.
  5. Framework is pipeline-oriented and can be adapted beyond Windows kernel driver analysis.