TGViewer
Linux Linux @sysadminoff · 2.13K subscribers
Post #19523 59
Microsoft Defender’s signed BTR.sys driver can erase security tools at boot

A Microsoft-signed driver built into Defender can be repurposed to remove antivirus and EDR components before they start, giving attackers with administrator-level privileges a powerful boot-time evasion technique. Check Point Research says the approach works from Windows 7 through Windows 11 25H2, bypasses common driver-blocking controls, and is not currently linked to real-world attacks.
Source

👉@sysadminoff

https://4sysops.com/archives/microsoft-defenders-signed-btr-sys-driver-can-erase-security-tools-at-boot/
More from @sysadminoff
  1. Oct 7, 2026Объявлены результаты конкурса «Код логики» На полях XXII Конференции разработчиков свободн…
  2. Oct 6, 2026📰 Debian's latest kernel security update has 1,313 reasons to patch AI-assisted bug hunti…
  3. Oct 6, 2026📰 Linux's ZRAM Reworked For Greater Memory Savings, Better Performance With today's very…
  4. Oct 6, 2026Windows 365 new features: Reserve, disaster recovery, display protection, and AVD Hybrid M…
  5. Oct 6, 2026Enable built-in Sysmon in Windows 11 with PowerShell Windows 11 now includes System Monito…
  6. Oct 6, 2026Dutch tax authority plans open-source replacement for Microsoft 365 The Dutch Tax and Cust…
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →