https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-driver-block-rules … If you are curious which drivers Windows blocks by default with HVCI and KMCI kernel mode kernel signing the list is available here. We are constantly updating and you can of course use supplemental policies to add whatever you want.
have you considered how much that is the exact same as how windows defender works?