logo

Microsoft Defender's Own Driver Can Be Weaponized to Delete Security Software at Boot

ID: faaedfed-ce41-5e2a-a665-95dbf21f02de

STIX ID: report--faaedfed-ce41-5e2a-a665-95dbf21f02de

Feed Name: The Hacker News

Threat Score
70/100

Date Published: 2026-08-21

Date Updated: 2026-08-22

Author: [email protected] (The Hacker News)

...
...

Check Point Research disclosed a technique that abuses the built-in Microsoft Defender boot-time driver BTR.sys to perform arbitrary kernel-level file and registry operations (including deleting Defender components) on Windows 7 through Windows 11 25H2; the researcher published a proof-of-concept (BTR_CLI), detailed the RC4-encrypted transaction format and deployment method, provided Sysmon/Windows IOCs, and recommended restricting SeLoadDriverPrivilege, while noting no evidence of active exploitation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.