CVE Tools
Back to feed
PoC public Windows Defender privilege-escalation BTR.sys Microsoft

Microsoft Defender's Own Driver Can Be Weaponized to Delete Security Software at Boot

The Hacker News·By The Hacker News··5 min read
CVE Tools coverage

Check Point Research has demonstrated a technique to weaponize Microsoft Defender's internal BTR.sys driver, enabling administrators to execute arbitrary kernel-level file and registry operations on Windows systems from Windows 7 through Windows 11 25H2. The proof-of-concept tool, BTR_CLI, leverages a hard-coded encryption key within the driver to install it as a boot service, allowing the removal of locked security components like WdFilter.sys during system startup before user-mode defenses initialize. Although the method requires existing administrative privileges and no traditional software flaw was exploited, the capability to strip endpoint protection using a native, signed Windows component poses a significant risk to defensive architectures.