Windows Defender Driver Weaponized to Bypass EDR and Execute Kernel Ops
cyb3rops · x · 2026-08-21
Check Point Research reveals that Windows Defender's Boot-Time Removal driver (BTR.sys) can be abused. Attackers with SeLoadDriverPrivilege can load malicious configs to make the legitimate driver perform Ring-0 file/registry operations, disabling security software and planting drivers without exploiting vulnerabilities. A demo tool BTRCLI was released.
More from Safety
- Sam Altman on the AI dilemma: trade-offs between loss of control and power centralization — r0ck3t23 · 2026-08-24
- Debate erupts over lethal military robots vs. failing civilian units — teortaxesTex · 2026-08-24
- Only 1 of 20 Potential Presidential Candidates Answered AI Pause Query — DavidSKrueger · 2026-08-24
- Chinese Transforming Robot Dog Sparks US Trade Policy Criticism — TinfoilTricorn · 2026-08-24
- Turkey blocks at least 12 Grok posts on national security grounds — Unusual_Variation293 · 2026-08-24
- Nature Comment: Provenance, not interpretability, grounds trust in autonomous science — gabepgomes · 2026-08-24