data
machine-readable feeds over the same dataset as the drivers index, so consumers do not have to parse HTML. Rebuilt with the site; the source data is refreshed daily by the scheduled rebuild.
GET /drivers.json
schema 1
The full family index. Public, no authentication, no rate limit. Served with
cache-control: public, must-revalidate, max-age=3600, stale-while-revalidate=86400
— the global /* rule merges its must-revalidate into the feed's own
directive. The dataset changes at most once per day (the scheduled rebuild), so the short TTL
with a long stale window lets a consumer pick up a same-day correction without a cache purge.
schemaVersion— integer, bumped when the shape changes.generatedAt— ISO-8601 timestamp of the build that produced the file.provenance.sources[]—id,url, and aversionwhere the source carries one (the Microsoft block list does).counts— totals for drivers, samples, blocked drivers, HVCI-loadable drivers and blocked families.hvciStatusLegend— maps eachhvciStatusvalue to its meaning.microsoftBlockedFamilies[]—nameanddenyHashCountper blocked family.
| field | type | meaning |
|---|---|---|
| slug | string | stable per-family id, also the anchor on /drivers |
| id | string | LOLDrivers record id |
| names | string[] | known filenames and tags for the family |
| category | string | LOLDrivers category |
| cve | string[] | CVE ids, empty when none are assigned |
| mitreId | string | MITRE ATT&CK technique id |
| verified | boolean | LOLDrivers verification flag |
| created | string | date the upstream record was created |
| companies | string[] | signing vendors seen across samples |
| resources | string[] | upstream reference URLs |
| sampleCount | number | known-vulnerable samples in the family |
| hvciLoadableCount | number | samples that load with HVCI enabled |
| hvciStatus | string | bypass | none | not-evaluated |
| msBlocked | boolean | present on Microsoft's block list |
| permalink | string | absolute URL back to the family row |
hvciStatus
three states, deliberately hvciLoadableCount === 0 on its own cannot tell "every sample was evaluated and
none loads" apart from "upstream never reported the field", so the status is explicit.
Treating an absence of data as a clean result is the mistake this avoids.
| value | meaning |
|---|---|
| bypass | at least one known sample loads with HVCI enabled |
| none | HVCI load status was reported for this family and no known sample loads |
| not-evaluated | upstream reported no HVCI load status for any sample of this family |
GET /drivers.csv
same projection as the JSON
Identical fields, flattened for spreadsheets and one-liners. Array fields are joined with
|. Every field is quoted; embedded quotes are doubled per RFC 4180. There is no
comment header line, so a strict CSV parser can read the file directly. Delivered as
virtualized-drivers.csv with content-disposition: attachment, so a
browser saves it instead of rendering it.
slug, id, names, category, cve, mitre_id, verified, created, companies, sample_count, hvci_loadable_count, hvci_status, ms_blocked, reference_url
GET /vault/data/driver-hashes.json
pro — schema 1
Per-sample hashes for direct ingestion into EDR, SIEM, AppLocker and WDAC tooling.
Authenticate with a session cookie or Authorization: Bearer vp_live_…;
see the vault for access. Served with cache-control: no-store.
microsoftBlockedFamilies[].hashes— the deny hashes from Microsoft's policy, as authentihashes: the image digest with the checksum and certificate table excluded. The policy mixes digest widths — 40-hex SHA-1 rules and 64-hex SHA-256 rules — so compare against the right one rather than assuming a length.drivers[].samples[]— per samplefilename,sha256(whole file),authentihash(SHA-256 of the image without the checksum and certificate table),company,version,signedandloadsDespiteHVCI.- All hashes are lowercase. A sample's
sha256and itsauthentihashare different digests over different byte ranges and are not interchangeable — pick the one your tooling compares against. Either can be empty when upstream recorded no such digest for that sample.
Per-sample hashes are deliberately not in the public feeds above; the public JSON and CSV carry family metadata only.
sources
Built from LOLDrivers and Microsoft's recommended vulnerable driver block list. Attribution belongs to those projects; this site aggregates and cross-references them.