Microsoft Defender's Own Driver Can Be Weaponized to Delete Security Software at Boot
Check Point revealed how Defender's legitimately signed boot-time driver can be co-opted for kernel-level file deletion—no exploit needed—undermining endpoint trust assumptions across Windows 7 to 11 25H2.
Summary written by editorial AI · Source link below
Check Point Research has disclosed a technique that uses Microsoft Defender's own legitimately signed boot-time remediation driver to perform arbitrary kernel-level file and registry operations on Windows systems ranging from Windows 7 through Windows 11 25H2, with no software flaw exploited and no driver imported from outside the machine.
The driver, BTR.sys (Boot Time Removal Tool), is a
Editorial Analysis
When a vendor's own signed driver becomes an attack tool, it erodes the trust chain that underpins endpoint security and challenges assumptions about driver-signing as a security boundary.
Validate that your EDR can detect abuse of the Defender remediation driver and test boot-time integrity controls such as HVCI and Secure Boot enforcement.
Microsoft Defender's own signed driver can be weaponised to disable security software at boot—review endpoint protection resilience with your security vendor.
Forward-looking interpretation drafted by editorial AI under human review — not a reproduction of the source. See methodology.
External link — opens at THN (Feedburner) in a new tab.
More from the Threat Intel Desk
- ToxicPanda Android malware uses VPN permissions to block Google Play6d
- New SynkLoader malware pushed in Microsoft Teams phishing campaign21 Aug
- U.S. Bank says breach claims related to fourth-party incident21 Aug
- The Good, the Bad and the Ugly in Cybersecurity – Week 3421 Aug
- Hackers abuse FTP server banners to deliver new Windows malware21 Aug