Microsoft Defender's Own Driver Can Be Weaponized to Delete Security Software at Boot
Check Point Research has disclosed a technique that uses Microsoft Defender's own legitimately signed boot-time remediation driver to perform arbitrary kernel-level file and registry operations on Windows systems ranging from Windows 7 through Windows 11 25H2, with no software flaw exploited and no driver imported from outside the machine. The driver, BTR.sys (Boot Time Removal Tool), is a
What happened
Check Point Research has disclosed a technique that uses Microsoft Defender's own legitimately signed boot-time remediation driver to perform arbitrary kernel-level file and registry operations on Windows systems ranging from Windows 7 through Windows 11 25H2, with no software flaw exploited and no driver imported from outside the machine. The driver, BTR.sys (Boot Time Removal Tool), is a
Why it matters
The incident may affect operational continuity, asset safety or trust around Microsoft. Watch for verified scope and remediation.
Affected entities
View evidence
1 reports · 1 original report · 1 independent
- The Hacker NewsPrimary source · Supports · EN · 100%Microsoft Defender's Own Driver Can Be Weaponized to Delete Security Software at Boot ↗
Claims
- Microsoft Defender's Own Driver Can Be Weaponized to Delete Security Software at Boot Observed
Conflicts
No material conflict detected in the available evidence.
Timeline
- First reported
Market move following event
Market reaction is not yet available for this asset and time window.