Microsoft Defender's Own Driver Can Be Weaponized to Delete Security Software at Boot
Check Point Research has demonstrated a technique to weaponize Microsoft Defender's internal BTR.sys driver, enabling administrators to execute arbitrary kernel-level file and registry operations on Windows systems from Windows 7 through Windows 11 25H2. The proof-of-concept tool, BTR_CLI, leverages a hard-coded encryption key within the driver to install it as a boot service, allowing the removal of locked security components like WdFilter.sys during system startup before user-mode defenses initialize. Although the method requires existing administrative privileges and no traditional software flaw was exploited, the capability to strip endpoint protection using a native, signed Windows component poses a significant risk to defensive architectures.