
Windows Defender’s own driver can leave systems defenseless
A Microsoft-signed Windows Defender remediation driver can be repurposed into a kernel-level “operation engine” capable of deleting files, modifying the registry and neutralizing security controls, according to new research from Check Point Research (CPR).
The technique does not exploit a vulnerability or rely on the traditional Bring Your Own Vulnerable Driver (BYOVD) model. Instead, it abuses functionality intentionally built into Defender’s Boot-Time Removal driver, “BTR.sys,” CPR researcher Jiří Vinopal said in a blog post.
Vinopal reverse-engineered the driver and its undocumented transaction format, finding that BTR.sys can be instructed to perform arbitrary file and registry operation...