Microsoft Defender Driver Weaponized to Delete Security Software at Boot

Executive Summary

Check Point Research revealed that Microsoft Defender’s signed boot‑time remediation driver, BTR.sys, can be abused to perform arbitrary kernel‑level file and registry operations, enabling the removal of security software during boot on Windows 7‑11 25H2. The technique requires no software flaw or external driver, relying solely on the legitimate driver.


Intelligence Metadata - Source Publisher: The Hacker News - Published Date: 2026-08-21T15:52:10+00:00 - Category: threat-intel

Original Description: Check Point Research has disclosed a technique that uses Microsoft Defender's own legitimately signed boot-time remediation driver to perform arbitrary kernel-level file and registry operations on Windows systems ranging from Windows 7 through Windows 11 25H2, with no software flaw exploited and no driver imported from outside the machine. The driver, BTR.sys (Boot Time Removal Tool), is a

"If we are facing in the right direction, all we have to do is keep on walking."

— Unknown
Source: The Hacker News