< Back to all clusters
[TECHNOLOGY] · 2 sources

started · updated

Microsoft Defender driver can be weaponized to disable security

Researchers at Check Point Research have identified a method to weaponize a legitimate Microsoft Defender component, the Boot-Time Removal (BTR.sys) driver, to perform privileged kernel-level operations. This technique does not rely on traditional memory corruption vulnerabilities or CVE exploits, but rather repurposes a trusted, Microsoft-signed driver to execute unauthorized actions.

The BTR.sys driver is part of the Microsoft Defender remediation infrastructure, embedded within MpEngine.dll. It is typically deployed to handle tasks that require a system reboot, such as removing files locked by the operating system. By reproducing the driver’s undocumented transaction protocol, attackers with administrative privileges could potentially use it to delete files, move directories, or modify registry keys from Ring 0, effectively neutralizing Endpoint Detection and Response (EDR) and antivirus protections.

Because the driver uses RC4-encrypted configurations and temporary service names, its legitimate activity can closely resemble malicious kernel-loader tradecraft, potentially complicating incident response investigations.

Entities

Check Point Research · Microsoft · Microsoft Defender