< BACK TO NEWS
importantSYS.SOURCE: The Hacker News2026-08-21T21:22:10+05:30

Microsoft Defender's BTR.sys Driver Exploited for Kernel-Level Security Software Removal

A research team discovered that Microsoft Defender's BTR.sys driver can be exploited to perform kernel-level file and registry operations, allowing deletion of security software during system boot without exploiting vulnerabilities. The technique leverages a trusted, built-in driver, bypassing standard security controls and requiring administrative privileges.

Check Point Research has disclosed a technique that uses Microsoft Defender's own legitimately signed boot-time remediation driver to perform arbitrary kernel-level file and registry operations on Windows systems ranging from Windows 7 through Windows 11 25H2, with no software flaw exploited and no driver imported from outside the machine.

The driver, BTR.sys (Boot Time Removal Tool), is a

Read original article

*** END OF TRANSMISSION ***