Microsoft Defender's Own Driver Can Be Weaponized to Delete Security Software at Boot
ID: faaedfed-ce41-5e2a-a665-95dbf21f02de
STIX ID: report--faaedfed-ce41-5e2a-a665-95dbf21f02de
Feed Name: The Hacker News
Check Point Research disclosed a technique that abuses the built-in Microsoft Defender boot-time driver BTR.sys to perform arbitrary kernel-level file and registry operations (including deleting Defender components) on Windows 7 through Windows 11 25H2; the researcher published a proof-of-concept (BTR_CLI), detailed the RC4-encrypted transaction format and deployment method, provided Sysmon/Windows IOCs, and recommended restricting SeLoadDriverPrivilege, while noting no evidence of active exploitation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
