<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Microsoft Defender's Own Driver Can Be Weaponized to Delete Security Software at Boot]]></title><description><![CDATA[<p dir="auto">Check Point Research has detailed a technique that abuses Microsoft Defender's own, legitimately signed boot-time remediation driver to perform arbitrary kernel-level file and registry operations. The attack surface spans Windows 7 through Windows 11 25H2, and notably, no software vulnerability is exploited, nor is any external driver imported onto the target machine.</p>
<p dir="auto">The component in question is <strong>BTR.sys</strong> (Boot Time Removal Tool), a driver that is already present and signed by Microsoft, making it a trusted part of the OS ecosystem.</p>
<ul>
<li><strong>Impact:</strong> An attacker with administrator privileges can leverage BTR.sys to delete or modify sensitive files and registry keys at boot, potentially disabling security products before the OS fully loads.</li>
<li><strong>Affected Systems:</strong> Windows 7, Windows 8.x, Windows 10, Windows 11 (up to 25H2), and corresponding Server versions.</li>
<li><strong>Exploitation:</strong> Requires prior admin-level access; no user interaction or external driver installation is needed.</li>
</ul>
<p dir="auto">Because the driver is Microsoft-signed, the technique effectively bypasses driver signature enforcement and persistent protection mechanisms that would normally block third-party drivers from loading. Check Point notes this is a design trade-off in the remediation tool rather than a flaw in the code itself.</p>
<p dir="auto">Given that the driver is a standard component of Defender, the abuse vector is highly consistent across supported Windows builds.</p>
<p dir="auto">Source: <a href="https://thehackernews.com/2026/08/microsoft-defenders-own-driver-can-be.html" target="_blank" rel="noopener noreferrer nofollow ugc">The Hacker News</a></p>
<p dir="auto">Is your organization actively monitoring for unusual BTR.sys usage during boot, or have you implemented additional integrity checks on signed drivers to mitigate this type of abuse?</p>
]]></description><link>https://xploitlk.com/topic/61/microsoft-defender-s-own-driver-can-be-weaponized-to-delete-security-software-at-boot</link><generator>RSS for Node</generator><lastBuildDate>Sat, 05 Sep 2026 12:37:44 GMT</lastBuildDate><atom:link href="https://xploitlk.com/topic/61.rss" rel="self" type="application/rss+xml"/><pubDate>Sun, 23 Aug 2026 06:37:36 GMT</pubDate><ttl>60</ttl></channel></rss>