Windows Defender Driver Weaponized to Bypass EDR and Execute Kernel Ops

cyb3rops · x · 2026-08-21

Check Point Research reveals that Windows Defender's Boot-Time Removal driver (BTR.sys) can be abused. Attackers with SeLoadDriverPrivilege can load malicious configs to make the legitimate driver perform Ring-0 file/registry operations, disabling security software and planting drivers without exploiting vulnerabilities. A demo tool BTRCLI was released.

Original post →

More from Safety

Safety channel →