← Back to feed
Vulnerabilities & PatchesEmerging1 sourceAug 20, 2026 · 16:39via Cyber Security News

Microsoft Defender Driver Can Be Weaponized to Disable EDR and AV From Windows Kernel

Brief

Microsoft Defender’s legitimate Boot-Time Removal (BTR.sys) driver can be repurposed to perform powerful kernel-level file and registry operations, potentially enabling attackers with administrative privileges to neutralize endpoint security protections.

The Check Point research does not describe a conventional vulnerability or memory-corruption flaw; instead, it exposes how a trusted, Microsoft-signed remediation component can become a Living-off-the-Land driver when its undocumented transaction protocol is reproduced.

BTR.sys Driver File Properties (Image source: Checkpoint)

Microsoft Defender Driver Can Be Weaponized

BTR. sys is embedded within Microsoft Defender’s MpEngine. dll and is deployed when Defender needs to complete a remediation task after reboot, such as removing a file locked by the operating system.

Read more on Cyber Security News