LOLDrivers and BYOVD Attacks
A customer recently came to us confused about an alert another provider had already closed. They run a split-SOC arrangement, and that provider’s EDR had fired on “a process loaded a driver with known vulnerabilities.” It was triaged, marked a true positive, and resolved. No phone call, no context, no “here is what this means…
$ cat full-post