CVE Tools

Microsoft Defender's Own Driver Can Be Weaponized to Delete Security Software at Boot

The Hacker NewsBy The Hacker News

PoC publicWindows DefenderBTR.sys

Our summary

Check Point Research has demonstrated a technique to weaponize Microsoft Defender's internal BTR.sys driver, enabling administrators to execute arbitrary kernel-level file and registry operations on Windows systems from Windows 7 through Windows 11 25H2. The proof-of-concept tool, BTR_CLI, leverages a hard-coded encryption key within the driver to install it as a boot service, allowing the removal of locked security components like WdFilter.sys during system startup before user-mode defenses initialize. Although the method requires existing administrative privileges and no traditional software flaw was exploited, the capability to strip endpoint protection using a native, signed Windows component poses a significant risk to defensive architectures.

Read at The Hacker News

The Hacker News publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store