
Microsoft-Signed Defender Driver Weaponized to Disable EDR and Antivirus
Microsoft Defender’s legitimate Boot-Time Removal driver, BTR.sys, can be repurposed to execute powerful kernel-level file and registry operations before many endpoint protections fully initialize. The technique, disclosed by Check Point Research, is not a traditional vulnerability involving memory corruption, privilege escalation, or a coding flaw. Instead, it shows how a trusted Microsoft-signed remediation component can […]
The post Microsoft-Signed Defender Driver Weaponized to Disable EDR and Antivirus appeared first on Cyber Security News.