BTR Reforged: Weaponizing Defender’s Remediation Driver as a Kernel Operation Primitive
ID: bd7c76b4-7eb8-54b3-8fc8-8aae21987ecb
STIX ID: report--bd7c76b4-7eb8-54b3-8fc8-8aae21987ecb
Feed Name: Check Point Research
**Research summary:** This paper reverse-engineers the Windows Defender Boot-Time Removal driver (BTR.sys), documents its RC4-encrypted transaction format and integrity checks, and demonstrates a Proof-of-Concept tool (BTR_CLI) that constructs valid transactions to instruct the signed driver to perform arbitrary file and registry operations from Ring 0. The report shows how, when staged to run at System Start (Start=1) in the "Boot Bus Extender" group, the driver can neutralize Defender components during a boot-time "golden window," outlines detection signals (ADS creation, Sysmon events, driver lineage), and provides mitigation and operational recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
