Microsoft Defender's BTR.sys Driver Exploited for Kernel-Level Security Software Removal
A research team discovered that Microsoft Defender's BTR.sys driver can be exploited to perform kernel-level file and registry operations, allowing deletion of security software during system boot without exploiting vulnerabilities. The technique leverages a trusted, built-in driver, bypassing standard security controls and requiring administrative privileges.
Check Point Research has disclosed a technique that uses Microsoft Defender's own legitimately signed boot-time remediation driver to perform arbitrary kernel-level file and registry operations on Windows systems ranging from Windows 7 through Windows 11 25H2, with no software flaw exploited and no driver imported from outside the machine.
The driver, BTR.sys (Boot Time Removal Tool), is a
*** END OF TRANSMISSION ***