logo

BTR Reforged: Weaponizing Defender’s Remediation Driver as a Kernel Operation Primitive

ID: bd7c76b4-7eb8-54b3-8fc8-8aae21987ecb

STIX ID: report--bd7c76b4-7eb8-54b3-8fc8-8aae21987ecb

Feed Name: Check Point Research

Threat Score
75/100

Date Published: 2026-08-20

Date Updated: 2026-08-20

Author: [email protected]

...
...

**Research summary:** This paper reverse-engineers the Windows Defender Boot-Time Removal driver (BTR.sys), documents its RC4-encrypted transaction format and integrity checks, and demonstrates a Proof-of-Concept tool (BTR_CLI) that constructs valid transactions to instruct the signed driver to perform arbitrary file and registry operations from Ring 0. The report shows how, when staged to run at System Start (Start=1) in the "Boot Bus Extender" group, the driver can neutralize Defender components during a boot-time "golden window," outlines detection signals (ADS creation, Sysmon events, driver lineage), and provides mitigation and operational recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.