⌬ virtualized.pro
← drivers

data

machine-readable feeds over the same dataset as the drivers index, so consumers do not have to parse HTML. Rebuilt with the site; the source data is refreshed daily by the scheduled rebuild.

GET /drivers.json

schema 1

The full family index. Public, no authentication, no rate limit. Served with cache-control: public, must-revalidate, max-age=3600, stale-while-revalidate=86400 — the global /* rule merges its must-revalidate into the feed's own directive. The dataset changes at most once per day (the scheduled rebuild), so the short TTL with a long stale window lets a consumer pick up a same-day correction without a cache purge.

  • schemaVersion — integer, bumped when the shape changes.
  • generatedAt — ISO-8601 timestamp of the build that produced the file.
  • provenance.sources[] — id, url, and a version where the source carries one (the Microsoft block list does).
  • counts — totals for drivers, samples, blocked drivers, HVCI-loadable drivers and blocked families.
  • hvciStatusLegend — maps each hvciStatus value to its meaning.
  • microsoftBlockedFamilies[] — name and denyHashCount per blocked family.
field type meaning
slug string stable per-family id, also the anchor on /drivers
id string LOLDrivers record id
names string[] known filenames and tags for the family
category string LOLDrivers category
cve string[] CVE ids, empty when none are assigned
mitreId string MITRE ATT&CK technique id
verified boolean LOLDrivers verification flag
created string date the upstream record was created
companies string[] signing vendors seen across samples
resources string[] upstream reference URLs
sampleCount number known-vulnerable samples in the family
hvciLoadableCount number samples that load with HVCI enabled
hvciStatus string bypass | none | not-evaluated
msBlocked boolean present on Microsoft's block list
permalink string absolute URL back to the family row

hvciStatus

three states, deliberately

hvciLoadableCount === 0 on its own cannot tell "every sample was evaluated and none loads" apart from "upstream never reported the field", so the status is explicit. Treating an absence of data as a clean result is the mistake this avoids.

value meaning
bypass at least one known sample loads with HVCI enabled
none HVCI load status was reported for this family and no known sample loads
not-evaluated upstream reported no HVCI load status for any sample of this family

GET /drivers.csv

same projection as the JSON

Identical fields, flattened for spreadsheets and one-liners. Array fields are joined with |. Every field is quoted; embedded quotes are doubled per RFC 4180. There is no comment header line, so a strict CSV parser can read the file directly. Delivered as virtualized-drivers.csv with content-disposition: attachment, so a browser saves it instead of rendering it.

slug, id, names, category, cve, mitre_id, verified, created, companies, sample_count, hvci_loadable_count, hvci_status, ms_blocked, reference_url

GET /vault/data/driver-hashes.json

pro — schema 1

Per-sample hashes for direct ingestion into EDR, SIEM, AppLocker and WDAC tooling. Authenticate with a session cookie or Authorization: Bearer vp_live_…; see the vault for access. Served with cache-control: no-store.

  • microsoftBlockedFamilies[].hashes — the deny hashes from Microsoft's policy, as authentihashes: the image digest with the checksum and certificate table excluded. The policy mixes digest widths — 40-hex SHA-1 rules and 64-hex SHA-256 rules — so compare against the right one rather than assuming a length.
  • drivers[].samples[] — per sample filename, sha256 (whole file), authentihash (SHA-256 of the image without the checksum and certificate table), company, version, signed and loadsDespiteHVCI.
  • All hashes are lowercase. A sample's sha256 and its authentihash are different digests over different byte ranges and are not interchangeable — pick the one your tooling compares against. Either can be empty when upstream recorded no such digest for that sample.

Per-sample hashes are deliberately not in the public feeds above; the public JSON and CSV carry family metadata only.

sources

Built from LOLDrivers and Microsoft's recommended vulnerable driver block list. Attribution belongs to those projects; this site aggregates and cross-references them.