Check Point Research has disclosed a technique that uses Microsoft Defender's own legitimately signed boottime remediation driver to perform arbitrary kernellevel file and registry operations on Windows systems ranging from Windows 7 through Windows 11 25H2, with no software flaw exploited and no driver imported from outside the machine. The driver, BTR.sys Boot Time Removal Tool, is a.📖 Read more.
🔗 Via "The Hacker News"
----------
👁️ Seen on @cibsecurity