Established 2026Friday, 21 August 2026
presents

The CloudySec Digest

The wires, edited.
← Front PageThreat Intel Desk
Threat Intel

Microsoft Defender's Own Driver Can Be Weaponized to Delete Security Software at Boot

Check Point revealed how Defender's legitimately signed boot-time driver can be co-opted for kernel-level file deletion—no exploit needed—undermining endpoint trust assumptions across Windows 7 to 11 25H2.

Summary written by editorial AI · Source link below

Filed by THN (Feedburner)1 min readRead at source ↗

Check Point Research has disclosed a technique that uses Microsoft Defender's own legitimately signed boot-time remediation driver to perform arbitrary kernel-level file and registry operations on Windows systems ranging from Windows 7 through Windows 11 25H2, with no software flaw exploited and no driver imported from outside the machine.

The driver, BTR.sys (Boot Time Removal Tool), is a

Editorial Analysis

Why it matters

When a vendor's own signed driver becomes an attack tool, it erodes the trust chain that underpins endpoint security and challenges assumptions about driver-signing as a security boundary.

What to do

Validate that your EDR can detect abuse of the Defender remediation driver and test boot-time integrity controls such as HVCI and Secure Boot enforcement.

Board brief

Microsoft Defender's own signed driver can be weaponised to disable security software at boot—review endpoint protection resilience with your security vendor.

Forward-looking interpretation drafted by editorial AI under human review — not a reproduction of the source. See methodology.

Continue at the source
Read the full report at THN (Feedburner)

External link — opens at THN (Feedburner) in a new tab.

§
Continue with

More from the Threat Intel Desk