Microsoft Defender's Own Driver Can Be Weaponized to Delete Security Software at Boot
Check Point revealed how Defender's legitimately signed boot-time driver can be co-opted for kernel-level file deletion—no exploit needed—undermining endpoint trust assumptions across Windows 7 to 11 25H2.
Summary written by editorial AI · Source link below
Check Point Research has disclosed a technique that uses Microsoft Defender's own legitimately signed boot-time remediation driver to perform arbitrary kernel-level file and registry operations on Windows systems ranging from Windows 7 through Windows 11 25H2, with no software flaw exploited and no driver imported from outside the machine.
The driver, BTR.sys (Boot Time Removal Tool), is a
Editorial Analysis
When a vendor's own signed driver becomes an attack tool, it erodes the trust chain that underpins endpoint security and challenges assumptions about driver-signing as a security boundary.
Validate that your EDR can detect abuse of the Defender remediation driver and test boot-time integrity controls such as HVCI and Secure Boot enforcement.
Microsoft Defender's own signed driver can be weaponised to disable security software at boot—review endpoint protection resilience with your security vendor.
Forward-looking interpretation drafted by editorial AI under human review — not a reproduction of the source. See methodology.
External link — opens at THN (Feedburner) in a new tab.
More from the Threat Intel Desk
- Attackers conceal phishing lures using invisible Unicode characters1d
- Attackers Hijack MikroTik Routers Through Internet-Exposed SSH Without Authentication1d
- Four REVSTEALER-Linked Modules Disable Windows Update and Defender to Run a Crypto Miner1d
- Attackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS Credentials2d
- Over 5,400 hacked sites serve ClickFix payloads stored on the blockchain2d