BTR.sys Driver Abuse Turns Defender Into an EDR/AV Bypass
ID: c8c0bed3-844a-53a7-bec1-0a99bed2f645
STIX ID: report--c8c0bed3-844a-53a7-bec1-0a99bed2f645
Feed Name: securityonline.info
Check Point Research analyzed BTR.sys, a signed Windows Defender boot-time remediation driver, and demonstrated a proof-of-concept that crafting encrypted Alternate Data Stream transactions can coerce the driver to perform kernel-level file and registry operations (including moving files into System32 and deleting Defender components) during an early boot "Golden Window." The technique requires local administrative SeLoadDriverPrivilege, was validated in a lab (no observed real-world abuse), and yields a stealthy EDR/AV bypass; defenders are advised to monitor ADS usage (e.g., ":changelist"), watch suspicious driver loads and System process file deletions, and restrict/audit SeLoadDriverPrivilege.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
