The Gap Between Initial Access and Encryption
Ransomware reports document initial access in detail. They document the encryptor in detail. The minute in between — where the endpoint agent quietly stops reporting — gets a single line in the timeline.
That minute is where the intrusion is won.
Modern ransomware operations follow a predictable sequence. Once an operator has local admin on a host, encryption is rarely the next move. Blinding the security sensor is. ESET’s 2026 research documents 90 EDR killers in active use, with 54 of them using BYOVD (bring your own vulnerable driver) techniques to disable endpoint defences before deploying the payload.
The technique works like this: the attacker cannot load an unsigned malicious driver, so they bring a signed driver from a legitimate vendor — often a hardware manufacturer or an old antivirus version — that contains a known vulnerability. Nothing is forged. The driver carries a valid signature from a real vendor, which means Windows trusts it. They’re simply loading an old, unpatched version of legitimate software that still contains a kernel-level flaw.
Once that driver loads and the attacker exploits the vulnerability, they reach Ring 0 — kernel-mode privileges with unrestricted access to system memory. From there, they terminate protected processes, tamper with kernel callbacks, and switch off telemetry from underneath the layer where the EDR operates. Tamper protection settings offer no defense here because they run at user-mode privilege level and cannot stop a tool that has already reached the kernel.
The File Operation Nobody Watches
Here’s what matters for prevention: that vulnerable driver has to land on disk before it can load.
It’s a file write operation. The attacker’s browser downloads the .sys file. Their remote access tool drops it to C:\Windows\System32\drivers. Their script writes it during the intrusion. Before the service registration, before the Ring 0 exploit, before the EDR dies — there’s a file write.
FileSure Defend operates at the Windows kernel level via a filter driver that intercepts file operations before they complete. A rule that blocks unauthorized programs from writing .sys files to the system stops the EDR killer at the earliest possible point in the attack chain.
The rule looks like this:
File name filter: *.sys
Operations: Write, Create
Program name filter: Deny all except authorized system management tools
Drive type: Hard drives
Result: Email clients, browsers, remote access tools, and scripts cannot write driver files to disk. The vulnerable driver payload never lands. No driver on disk means no service registration, no kernel exploit, no dead EDR, no ransomware deployment.
The article documents exactly why this matters. Check Point found more than 2,500 distinct variants of a single driver, TrueSight.sys, produced by tweaking eight bytes in the PE header — each with a unique hash and a still-valid signature. In April 2026, an attacker used ktapi.sys, a Kontron industrial driver that wasn’t on any public blocklist at the time.
Signature-based blocklists stop known vulnerable drivers. Capable operators rotate to signed drivers that aren’t on the list yet. A kernel-level file operation policy doesn’t care which driver it is. It cares whether the program doing the writing is authorized to write driver files. If it’s not authorized, the write is blocked — whether the driver is on a blocklist or not.
The Control That Fires First
Most organizations layer controls: EDR for known threats, behavioral detection for anomalies, Microsoft’s vulnerable driver blocklist for known bad drivers. All useful. But if the attacker rotates to a driver that’s not blocklisted yet, those controls miss. And by the time your MDR team notices the agent went silent, the best evidence was written twenty minutes earlier by a .sys file nobody was watching.
FileSure Defend gives you the control that fires first — before the driver lands, before it loads, before your other defenses go blind. It runs on every Windows version from XP through Windows 11 and Server 2003 through Server 2022, including the legacy systems where modern EDR won’t install.
Start a free 21-day trial at bystorm.com and see it block a simulated driver drop in real time.
Source: Killing the Sensor First: What Happens Before the Encryptor Runs
Category: Ransomware
Tags: edr killer, byovd, ring 0 exploit, vulnerable driver, kernel filter driver, file system security, ransomware prevention, endpoint protection