{"id":9218,"date":"2026-08-24T11:47:59","date_gmt":"2026-08-24T11:47:59","guid":{"rendered":"https:\/\/cybersecurityinfocus.com\/?p=9218"},"modified":"2026-08-24T11:47:59","modified_gmt":"2026-08-24T11:47:59","slug":"windows-defenders-own-driver-can-leave-systems-defenseless","status":"publish","type":"post","link":"https:\/\/cybersecurityinfocus.com\/?p=9218","title":{"rendered":"Windows Defender\u2019s own driver can leave systems defenseless"},"content":{"rendered":"<div>\n<div class=\"grid grid--cols-10@md grid--cols-8@lg article-column\">\n<div class=\"col-12 col-10@md col-6@lg col-start-3@lg\">\n<div class=\"article-column__content\">\n<div class=\"container\"><\/div>\n<p class=\"wp-block-paragraph\">A Microsoft-signed Windows Defender remediation driver can be repurposed into a kernel-level \u201coperation engine\u201d capable of deleting files, modifying the registry and neutralizing security controls, according to new research from Check Point Research (CPR).<\/p>\n<p class=\"wp-block-paragraph\">The technique does not exploit a vulnerability or rely on the traditional Bring Your Own Vulnerable Driver (<a href=\"https:\/\/www.csoonline.com\/article\/3600750\/infostealers-are-using-byovd-to-steal-critical-system-data.html\" target=\"_blank\" rel=\"noopener\">BYOVD<\/a>) model. Instead, it abuses functionality intentionally built into Defender\u2019s Boot-Time Removal driver, \u201cBTR.sys,\u201d CPR researcher Ji\u0159\u00ed Vinopal said in a blog <a href=\"https:\/\/research.checkpoint.com\/2026\/btr-reforged-weaponizing-defenders-remediation-driver-as-a-kernel-operation-primitive\/\" target=\"_blank\" rel=\"noopener\">post<\/a>.<\/p>\n<p class=\"wp-block-paragraph\">Vinopal reverse-engineered the driver and its undocumented transaction format, finding that BTR.sys can be instructed to perform arbitrary file and registry operations from kernel mode.<\/p>\n<p class=\"wp-block-paragraph\">BTR.sys is a legitimate Microsoft-signed component and is used when Defender needs to perform remediation requiring a reboot, such as deleting a locked file.<\/p>\n<p class=\"wp-block-paragraph\">CPR team has shared a proof-of-concept tool, BTR_CLI, that demonstrates the technique on Windows versions ranging from Windows 7 through fully updated Windows 11 25H2.<\/p>\n<p class=\"wp-block-paragraph\">The attack path remains open with no evidence of in-the-wild abuse yet, as Microsoft\u2019s Security Response Center (MSRC) found it \u201cdid not meet the criteria for immediate servicing.\u201d<\/p>\n<p class=\"wp-block-paragraph\">The attack relies on pre-existing privileges, MSRC reportedly said.<\/p>\n<h2 class=\"wp-block-heading\"><a><\/a>A Defender cleanup mechanism turned malicious<\/h2>\n<p class=\"wp-block-paragraph\">The technique abuses the way BTR.sys receives its instructions. Rather than exposing a conventional IOCTL interface, the one-shot driver reads an encrypted configuration stored in an Alternate Data Stream attached to the driver.<\/p>\n<p class=\"wp-block-paragraph\">CPR found that the configuration uses RC4 encryption with a hard-coded 256-byte key and a custom CRC-32 integrity check.<\/p>\n<p class=\"wp-block-paragraph\">Once decrypted, the configuration contains a sequence of actions like file deletion, directory deletion, file moves, and registry operations. Registry operations found possible included deleting registry keys and values, setting registry values, arbitrary registry modification, and, potentially, persistence or security control tampering.<\/p>\n<p class=\"wp-block-paragraph\">When the destination is set to System32, the file-move primitive can become an arbitrary file-write capability, Vinopal noted.<\/p>\n<p class=\"wp-block-paragraph\">The abuse was automated with BTR_CLI, including the extraction of the legitimate driver from the local Defender installation, construction of the encrypted transaction, and loading the driver. Using the target machine\u2019s own copy of BTR.sys, the tool avoids introducing external drivers as with conventional <a href=\"https:\/\/www.csoonline.com\/article\/3600750\/infostealers-are-using-byovd-to-steal-critical-system-data.html\">BYOVD <\/a>attacks, CPR noted.<\/p>\n<p class=\"wp-block-paragraph\">The researchers identified 18 unique Microsoft-signed 64-bit versions of the driver and found the same transaction format and RC4 key across the versions examined.<\/p>\n<p>Microsoft did not immediately respond to CSO\u2019s request for comment.<\/p>\n<h2 class=\"wp-block-heading\"><a><\/a>Boot timing made things worse<\/h2>\n<p class=\"wp-block-paragraph\">CPR also flagged where BTR.sys sits in Windows\u2019 boot sequence. The driver cannot run as a traditional Start=0 boot driver, but can execute very early in Phase 1 when configured as a Start=1 system driver in the Boot Bus Extender group.<\/p>\n<p class=\"wp-block-paragraph\">This, Vinopal noted, creates a \u201cGolden Window\u201d as the filesystem is already available for modification, but important security services and user-mode protection components have yet to start. \u201cThe primary AV service starts roughly 34 seconds after the BTR driver has finished its work,\u201d he said.<\/p>\n<p class=\"wp-block-paragraph\">CPR demonstrated that this timing could be used to delete Defender binaries and modify Defender-related registry keys before the protection services could launch. CPR said signature-based blocking is ineffective because BTR.sys is legitimate and recommended using behavioral context instead. Looking for signs that the driver is being used outside its normal Defender workflows, such as unusual process lineage and unexpected file or registry activity, may help, it said.<\/p>\n<\/div>\n<\/div>\n<\/div>\n<\/div>","protected":false},"excerpt":{"rendered":"<p>A Microsoft-signed Windows Defender remediation driver can be repurposed into a kernel-level \u201coperation engine\u201d capable of deleting files, modifying the registry and neutralizing security controls, according to new research from Check Point Research (CPR). The technique does not exploit a vulnerability or rely on the traditional Bring Your Own Vulnerable Driver (BYOVD) model. Instead, it [&hellip;]<\/p>\n","protected":false},"author":0,"featured_media":9219,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3],"tags":[],"class_list":["post-9218","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-education"],"_links":{"self":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts\/9218"}],"collection":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"replies":[{"embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=9218"}],"version-history":[{"count":0,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts\/9218\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/media\/9219"}],"wp:attachment":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=9218"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=9218"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=9218"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}