The driver's seat to ransomware. episode artwork

EPISODE · Aug 1, 2026 · 23 MIN

The driver's seat to ransomware.

from Research Saturday · host N2K Networks

This week, we are joined by Marcus Hutchins, Principal Threat Researcher at Expel, sharing their work on "Not very gentlemanly: Analyzing a zero-day exploit used by The Gentlemen ransomware to disable targets’ EDRs." Researchers examine how the Gentlemen ransomware group used a previously unknown zero-day vulnerability in a legacy Windows driver to disable endpoint detection and response (EDR) tools before deploying ransomware. The report details the group's advanced bring-your-own-vulnerable-driver (BYOVD) techniques, which bypass multiple Windows security protections to gain kernel-level access and terminate protected security software. It also outlines defensive measures organizations can take, including enabling Windows Defender Application Control (WDAC), virtualization-based security (VBS), and vulnerable driver blocklists to reduce the risk of similar attacks. The research and executive brief can be found here: Not very gentlemanly: Analyzing a zero-day exploit used by The Gentlemen ransomware to disable targets’ EDRs

Episode metadata supplied by the publisher feed · Published Aug 1, 2026

Embed this episode

NOW PLAYING

The driver's seat to ransomware.

0:00 23:52

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of Research Saturday?

This episode is 23 minutes long.

When was this Research Saturday episode published?

This episode was published on August 1, 2026.

Can I download this Research Saturday episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!