Last updated: September 29, 2026 at 8:42 AM UTC
All 891 Vulnerability 357 Breach 144 Threat 383 Defense 7
Tag: btr-sys (1 article)Clear

Microsoft Defender's own boot driver can be turned against security tools

Check Point researchers showed at Black Hat that Microsoft Defender's own legitimately signed boot-time cleanup driver, BTR.sys, can be abused to delete security software during startup. The driver, bundled inside Defender to finish removing malware after a reboot, can perform arbitrary kernel-level file and registry operations, and a released proof-of-concept wiped the entire Defender stack from a fully updated Windows 11 machine with tamper protection on. Unlike bring-your-own-vulnerable-driver attacks, this uses a driver present in every Windows since Windows 7, so it cannot be blocklisted. It requires administrator rights with a specific privilege, so Microsoft considers it a trust-boundary issue rather than a bug and will not patch it.

Check
Restrict the SeLoadDriverPrivilege to only accounts that truly need it, since the technique depends on it, and build detection for unexpected loading of the BTR.sys boot driver.
Affected
Windows systems from Windows 7 through 11 where an attacker gains administrator rights with SeLoadDriverPrivilege; they can use Defender's own signed boot driver to delete endpoint security tools before those tools load.
Fix
Limit local administrator rights and the driver-load privilege, monitor for boot-time driver abuse and security services vanishing, and prioritize detection engineering while the technique is public but not yet seen in attacks.