Microsoft Defender's Own Driver Can Be Weaponized to Delete Security Software at Boot
Check Point Research has discovered a method to weaponize Microsoft Defender's own built-in boot-time remediation driver (BTR.sys) to delete security software and manipulate Windows systems. This technique, dubbed ‘BTR Reforged,’ leverages a driver present on all Windows versions since 7, and doesn’t require exploiting a vulnerability. While currently not actively used, the research demonstrates a potential attack vector that could be exploited with administrator privileges. Microsoft has stated that a patch is not planned due to the reliance on existing administrative access.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
