DriverJack Turning NTFS and Emulated ROFs into an Infection
Alessandro Magnosi
DEF CON 32 Main Stage · Day 1 · Main Stage
Overview
Alessandro Magnosi's talk, "DriverJack Turning NTFS and Emulated ROFs into an Infection," introduces a novel and stealthy technique for loading malicious kernel drivers on Windows 11 systems. This research, developed by Magnosi and Jonas Leak, leverages specific NTFS features and a CDFS bug to bypass conventional driver loading mechanisms and, critically, evade the associated Windows event logs that typically alert defenders to driver installations. The technique, dubbed DriverJack, represents a significant advancement in kernel-level persistence and evasion, particularly relevant for sophisticated adversaries targeting high-value environments.

Key moments
- 0:00 Introduction to DriverJack: abusing NTFS and CDFs
- 1:50 Motivation: Weaponizing ISOs for OT kernel rootkit deployment
- 3:00 Challenges: Bypassing installer integrity checks on ISOs
- 3:58 Traditional driver loading and event log evasion attempts
- 5:00 Introducing core DriverJack libraries: IOCDFs lib and DriverJack
- 7:45 Coupling P: Preserving DLL exports for stealthy side-loading
DriverJack Turning NTFS and Emulated ROFs into an Infection
Speakers: Alessandro Magnosi
Conference: DEF CON 32
YouTube: https://www.youtube.com/watch?v=kWSP4F5dxTw
Overview
Alessandro Magnosi's talk, "DriverJack Turning NTFS and Emulated ROFs into an Infection," introduces a novel and stealthy technique for loading malicious kernel drivers on Windows 11 systems. This research, developed by Magnosi and Jonas Leak, leverages specific NTFS features and a CDFS bug to bypass conventional driver loading mechanisms and, critically, evade the associated Windows event logs that typically alert defenders to driver installations. The technique, dubbed DriverJack, represents a significant advancement in kernel-level persistence and evasion, particularly relevant for sophisticated adversaries targeting high-value environments.
The motivation for this research stemmed from a real-world operational technology (OT) engagement where the objective was to deploy a kernel rootkit on OT workstations. Traditional methods for loading drivers, such as creating a service or using NtLoadDriver, generate discernible system events (Event ID 11 and Event ID 6) that security solutions monitor. DriverJack aims to circumvent these detections, providing a method for adversaries to achieve deep system compromise without leaving the standard forensic footprints.
This talk is crucial for understanding emerging threats to Windows security, especially in sensitive environments like industrial control systems (ICS) where system integrity and stealth are paramount for attackers. By demonstrating how to weaponize common file system features and widely distributed update media (like ISOs), Magnosi highlights a critical blind spot in current defensive strategies and offers insights into the evolving landscape of kernel-mode malware.
Background
▶ Watch: Introduction to DriverJack: abusing NTFS and CDFs (0:00)
The journey to DriverJack began in 2022 with initial research by Alessandro Magnosi and Jonas Leak into abusing ISO files to load malicious drivers on Windows. This early work laid the groundwork but was temporarily set aside. The project gained renewed urgency and direction in 2023 during an OT engagement. The primary goal of this engagement was to deploy a kernel rootkit on OT workstations, necessitating a highly stealthy driver loading mechanism. The team discovered they could tamper with ISO files distributed to machines via an update catalog, presenting a perfect opportunity to weaponize their earlier research.
The objective was not merely to bypass Mark-of-the-Web (MotW), a common technique for weaponizing ISOs, but to achieve deeper system compromise and persistence. This included backdooring DLLs in various software to intercept communications, particularly those interacting with PLCs (Programmable Logic Controllers), using techniques like DLL side-loading, hooking, or DLL proxying. The ultimate aim, however, was the stealthy deployment of a kernel driver.
A significant challenge arose when targeting specific software, such as Siemens Step 7 installation media. Step 7 is distributed via ISO files and employs a robust, two-layer integrity checking bootstrap process before launching its installer. This means that to execute malicious code, an attacker must find a way to inject payloads without tampering with existing DLLs or executables on the disk, thereby preserving the integrity checks.
Traditional methods for loading Windows kernel drivers involve either creating a service using CreateService and StartService API calls or directly invoking the NtLoadDriver function. While NtLoadDriver is considered more stealthy as it bypasses the event logs associated with service creation, both methods invariably generate specific Windows system events. Specifically, Event ID 11 (Load Driver) and Event ID 6 (Driver Loaded Information) provide detailed telemetry about the loaded driver, including its path and name. These events serve as crucial indicators for security monitoring solutions. The core motivation behind DriverJack was to develop a technique that could completely bypass these event logs, rendering the driver loading process invisible to conventional detection mechanisms. To achieve this, Magnosi's team developed a suite of tools, with IOCDFs lib and DriverJack forming the core of the driver loading technique, complemented by collateral projects like RPC exact for stealthy process execution and Interleaver (including Coupling P) for PE manipulation and DLL export preservation.
Key Findings
▶ Watch: Challenges: Bypassing installer integrity checks on ISOs (3:00)
The central discovery presented in this talk is DriverJack, a sophisticated technique that enables the loading of unsigned kernel drivers on Windows 11 by exploiting specific NTFS features and a CDFS bug. This method fundamentally alters how a malicious driver can be introduced into the operating system, bypassing established security controls and detection mechanisms designed to monitor driver installations.
The primary contribution of DriverJack is its ability to evade Windows driver load events. Unlike traditional driver loading methods that generate Event ID 11 (Load Driver) and Event ID 6 (Driver Loaded Information), DriverJack's approach is designed to circumvent the logging mechanisms tied to these events. This allows an attacker to achieve kernel-level persistence with a significantly reduced forensic footprint, making detection much more challenging for security analysts and automated systems.
Another key finding is the practical applicability of this technique in Operational Technology (OT) environments and for supply chain attacks. The research was directly motivated by an OT engagement, where the goal was to deploy a kernel rootkit via tampered ISO files distributed through an update catalog. The ability to back-door integrity-checked installation media, such as Siemens Step 7, without triggering integrity alerts, demonstrates a powerful vector for initial access and persistence within highly secured industrial networks. This highlights a critical vulnerability in how software updates are validated and deployed in these sensitive environments.
The development of two core libraries, IOCDFs lib and DriverJack, represents the practical implementation of this research. These libraries are specifically crafted to interact with the underlying file system structures and exploit the identified vulnerabilities to facilitate the driver loading process. Additionally, the talk introduces collateral projects like RPC exact, a less common method for executing code on Windows processes without requiring executable memory allocation, and Interleaver, a PE manipulation library that includes Coupling P for preserving existing DLL exports during side-loading operations. These supplementary tools enhance the overall stealth and effectiveness of the attack chain, allowing for comprehensive compromise and control.
Technical Deep Dive
▶ Watch: Traditional driver loading and event log evasion attempts (3:58)
The core of the DriverJack technique revolves around the sophisticated abuse of NTFS features and an unspecified CDFS bug to achieve stealthy kernel driver loading on Windows 11. While the precise technical details of the CDFS bug itself are not extensively elaborated upon in the transcript, the talk clearly indicates that its exploitation, in conjunction with NTFS functionalities, is instrumental in bypassing standard driver loading procedures and their associated logging.
The context of ISO files and "emulated ROFs" (Read-Only File Systems) is critical here. ISOs typically contain a CDFS (Compact Disc File System), which is designed for read-only media. When an ISO is mounted, Windows presents its contents as a file system. The hypothesis, strongly implied by the talk's title and description, is that by manipulating the structure of an ISO (a CDFS) and then leveraging certain NTFS features, it's possible to trick the operating system into loading a driver. This loading occurs in a manner that circumvents the internal mechanisms responsible for registering and logging driver loads via CreateService or NtLoadDriver.
The traditional driver loading path involves explicit API calls that are hooked and monitored by the Windows kernel for security logging. DriverJack, however, appears to exploit a more fundamental interaction between the file system drivers (NTFS and CDFS) and the kernel's driver management components. This suggests that the malicious driver might be introduced or activated during the processing or mounting of the specially crafted file system, rather than through a direct, auditable API call. For instance, if the CDFS bug allows for arbitrary code execution or a controlled data overwrite within the kernel's file system parsing routines, this could potentially be leveraged to initiate driver loading without the usual event generation.
The NTFS features mentioned could relate to how Windows handles file system metadata, alternate data streams, or symbolic links, which could be abused to obscure the true nature or location of the malicious driver. When an ISO is tampered with and then mounted, the interaction between the emulated CDFS and the host's NTFS environment (or even just the kernel's handling of the CDFS) could create a window for exploitation. This could involve, for example, a scenario where a driver is loaded as part of a file system filter or a similar low-level component, which is then initiated by the system during the processing of the malformed ISO.
The talk highlights the development of two primary libraries: IOCDFs lib and DriverJack. These libraries are the practical implementation of the research, designed to craft the malicious ISOs and execute the driver loading technique. IOCDFs lib likely focuses on manipulating the ISO file structure, potentially exploiting the CDFS bug to embed the driver and trigger its loading. DriverJack would then be the orchestrating component, responsible for preparing the environment and initiating the sequence that leads to the silent driver load.
The speaker's mention of Siemens Step 7 installation media as a target illustrates the method's sophistication. Step 7 installers incorporate a bootstrap with a two-layer integrity check. To successfully back-door such an installer, the malicious driver and any associated payloads must be injected without altering the integrity of the existing executables or DLLs that are subject to these checks. This implies a highly precise manipulation of the ISO structure, possibly by adding new, ostensibly legitimate, files or leveraging existing, overlooked structures within the CDFS that are not covered by the integrity verification. The goal is to ensure that the installer's bootstrap successfully launches, but then subsequently loads the malicious driver via the DriverJack technique, ideally before the installer's own integrity checks complete or in a manner that bypasses them entirely.
The overall technical approach, therefore, is a multi-stage attack:
- ISO Tampering: Creating a specially crafted ISO file containing the malicious driver and potentially other payloads. This step involves leveraging
IOCDFs libto exploit the CDFS bug and embed the driver in a way that avoids integrity checks of the legitimate software. - Deployment: Distributing the tampered ISO, often via an update catalog, to target machines.
- Execution: When the ISO is mounted and the legitimate installer is run, the DriverJack technique is activated. This leverages the interaction between the emulated CDFS and NTFS features to load the kernel driver silently.
- Evasion: The driver is loaded without generating Event ID 11 or Event ID 6, making it invisible to standard security monitoring tools.
This method represents a sophisticated bypass of Windows' driver loading security model, moving beyond known techniques like signed driver abuse or vulnerable driver exploitation to a novel approach that manipulates fundamental file system interactions.
Demo / Proof of Concept
▶ Watch: Introducing core DriverJack libraries: IOCDFs lib and DriverJack (5:00)
The talk outlines the development and application of the DriverJack technique through several proof-of-concept (POC) implementations, demonstrating its efficacy in real-world scenarios. The initial work in 2022 with Jonas Leak involved creating a POC to abuse ISOs for malicious driver loading, setting the foundation for the current research.
A significant practical demonstration of DriverJack's capabilities emerged from the OT engagement in 2023. Here, the team successfully back-doored Siemens Step 7 installation media. This specific scenario served as a robust proof of concept for several reasons:
- Real-world Applicability: Step 7 installations are commonly deployed via ISOs in industrial environments, making it a highly relevant target.
- Integrity Bypass: Step 7 utilizes a bootstrap that performs two layers of integrity checks on the disk content before launching the installer. The ability to inject malicious code (including the kernel driver) without tampering with existing DLLs or executables that would trigger these checks proved the stealth and sophistication of the DriverJack technique. The malicious driver was presumably embedded in a way that the legitimate installer would still launch, but the driver would be loaded silently in the background.
- Kernel Rootkit Deployment: The ultimate goal of this engagement was to deploy a kernel rootkit, which was successfully achieved through the DriverJack method, demonstrating its power for deep system compromise.
While the specific code for IOCDFs lib and DriverJack was not fully shared in the public presentation, the speaker did mention sharing a simple POC from a collateral project: Coupling P (Coupling Preserve). This tool is part of the broader Interleaver PE manipulation library and addresses a common challenge in DLL side-loading. Traditional DLL side-loading frameworks often involve cloning a target DLL's export address table into a malicious DLL, a process that can be destructive to any existing exports in the payload DLL. Coupling P solves this by preserving the payload DLL's existing export address table and simply adding the forwards afterward. This POC, available on Magnosi's GitHub page, demonstrates a component of the overall toolset designed to enhance stealth and functionality for various payload delivery techniques, including those used in conjunction with DriverJack.
The combination of successful real-world application in an OT environment and the release of related utility POCs underscores the practical and sophisticated nature of the DriverJack research. It moves beyond theoretical exploitation to demonstrated capability against hardened targets.
Defensive Implications
▶ Watch: Coupling P: Preserving DLL exports for stealthy side-loading (7:45)
The DriverJack technique poses significant challenges for defenders, necessitating a re-evaluation of existing security strategies and a focus on advanced detection methods. The primary defensive implication is the bypass of standard Windows driver load events. Traditional security information and event management (SIEM) systems and Endpoint Detection and Response (EDR) solutions often rely on monitoring Event ID 11 (Load Driver) and Event ID 6 (Driver Loaded Information) for detecting unauthorized or suspicious kernel driver activity. Since DriverJack aims to load drivers without generating these events, existing detection rules tied to these specific log entries will be ineffective.
Defenders must therefore broaden their scope beyond conventional event log monitoring. This includes:
- Enhanced Integrity Validation for Software Updates: The attack vector of tampering with ISO files distributed via update catalogs, especially in OT environments, highlights a critical supply chain vulnerability. Organizations must implement robust, multi-layered integrity checks on all software updates and installation media, not just at rest but also during deployment and execution. This means validating cryptographic signatures, hashes, and potentially even behavioral analysis of installers to detect subtle modifications that might not trigger standard integrity alarms.
- Deep File System Monitoring: The exploitation of NTFS features and a CDFS bug suggests that monitoring file system interactions at a deeper level is crucial. This could involve:
- Tracking unexpected file system driver loads or modifications: Any unusual activity from
ntfs.sysorcdfs.sys(or related filter drivers) that deviates from baseline behavior warrants investigation. - Monitoring access to kernel memory or driver objects outside of standard API calls: If a driver is loaded through an obscure file system interaction, its presence in kernel memory might be identifiable through memory forensics or kernel integrity monitoring tools.
- Analyzing file system metadata and structures: Detecting anomalies in how files are structured within ISOs or on disk, especially those that deviate from standard specifications for CDFS or NTFS, could indicate tampering.
- Behavioral Analysis of System Boot and Driver Initialization: Instead of relying solely on explicit driver load events, defenders should focus on detecting the effects of a loaded driver. This includes:
- Unexpected kernel module presence: Tools that enumerate loaded kernel modules should be able to identify the malicious driver, even if its loading was stealthy.
- Anomalous kernel callbacks or hooks: Rootkits often establish hooks or modify kernel callbacks. Monitoring for new or modified callbacks could reveal the presence of a stealthily loaded driver.
- Unusual process behavior or resource utilization: While not directly indicative of driver loading, the subsequent actions of a kernel rootkit (e.g., intercepting communications, manipulating processes) might generate detectable anomalies.
- Network-Level Monitoring for OT Environments: Given the focus on OT, monitoring network communications to and from PLCs for unexpected patterns, data exfiltration, or command and control (C2) traffic is vital. Even if the kernel driver is stealthy, its malicious payload might interact with the network.
- Reviewing Third-Party Software and Update Processes: Organizations, particularly in critical infrastructure, need to scrutinize the security practices of their software vendors and the channels through which updates are delivered. The ability to tamper with installation media implies a potential compromise in the software supply chain.
- Advanced Memory Forensics: Post-compromise analysis using memory forensics tools can often reveal loaded kernel modules and their associated code, even if they were loaded in an evasive manner. Regular memory snapshots and analysis can help identify persistent threats.
In conclusion, DriverJack forces defenders to move beyond signature-based and superficial event-based detections towards more sophisticated behavioral analysis, deep system monitoring, and robust supply chain security practices, especially concerning file system interactions and software deployment.
Key Takeaways
- DriverJack Enables Stealthy Kernel Driver Loading: This technique allows malicious kernel drivers to be loaded on Windows 11 by exploiting specific NTFS features and a CDFS bug, bypassing traditional detection methods.
- Evades Standard Driver Load Events: DriverJack specifically aims to circumvent the generation of Event ID 11 (Load Driver) and Event ID 6 (Driver Loaded Information), which are critical indicators for most security monitoring solutions.
- Significant Threat to OT and Supply Chains: The research was motivated by an OT engagement and demonstrated successful backdooring of integrity-checked ISOs like Siemens Step 7 installation media, highlighting a potent vector for supply chain attacks in critical infrastructure.
- Requires Advanced Detection Beyond Event Logs: Defenders must shift towards deeper system monitoring, including file system integrity checks, kernel memory analysis, and behavioral detection, as traditional event-based monitoring is rendered ineffective.
- Leverages Custom Tooling: The technique is implemented through specialized libraries,
IOCDFs libandDriverJack, which interact with low-level file system components to achieve the evasive driver load. - Highlights File System Vulnerabilities: The talk underscores that vulnerabilities or unexpected interactions within core file system components (NTFS, CDFS) can be weaponized for highly stealthy kernel-level compromise.
About the Speaker(s)
Alessandro Magnosi, who goes by the online handle Clets Virus, is a security researcher currently working for BSI (British Standards Institute). His primary focus is on research, but a significant portion of his daily work involves consulting in adversary simulation, device security, and application security (appsec). He is active on GitHub and Twitter, where he encourages others to reach out. Magnosi collaborated with Jonas Leak from City Club on the initial proof-of-concept development for this project in 2022.
Reviews
Dr. Zero (Offensive Security Researcher) — MUST SEE
Alessandro Magnosi's "DriverJack" research unveils a highly sophisticated and stealthy method for loading unsigned kernel drivers on Windows 11 by exploiting specific NTFS features and an undisclosed CDFS bug. Critically, this technique bypasses the generation of standard Windows driver load events (Event ID 11 and 6), rendering it invisible to most conventional EDR and SIEM solutions. The work, motivated by a real-world OT engagement to backdoor Siemens Step 7 installation media with two-layer integrity checks, represents a significant leap in kernel-level persistence and evasion, forcing a fundamental rethink of defensive strategies, especially in critical infrastructure environments.
Heather Calloway (CISO) — MUST SEE
Magnosi's 'DriverJack' research presents a critical challenge to established Windows security models by demonstrating stealthy kernel driver loading that bypasses standard event logging. This is not merely a technical exploit; it exposes fundamental weaknesses in supply chain integrity, particularly in OT environments, and demands a re-evaluation of how organizations assure system integrity and detect advanced persistent threats at the kernel level. Every CISO and security leader needs to understand the implications for their risk posture and defensive strategy.