Microsoft Defender’s signed BTR.sys driver can erase security tools at boot
A Microsoft-signed driver built into Defender can be repurposed to remove antivirus and EDR components before they start, giving attackers with administrator-level privileges a powerful boot-time evasion technique. Check Point Research says the approach works from Windows 7 through Windows 11 25H2, bypasses common driver-blocking controls, and is not currently linked to real-world attacks.
Source
👉@sysadminoff
https://4sysops.com/archives/microsoft-defenders-signed-btr-sys-driver-can-erase-security-tools-at-boot/
Post #19523
59
