Microsoft Defender Driver Can Be Weaponized to Disable EDR and AV From Windows Kernel
Brief
Microsoft Defender’s legitimate Boot-Time Removal (BTR.sys) driver can be repurposed to perform powerful kernel-level file and registry operations, potentially enabling attackers with administrative privileges to neutralize endpoint security protections.
The Check Point research does not describe a conventional vulnerability or memory-corruption flaw; instead, it exposes how a trusted, Microsoft-signed remediation component can become a Living-off-the-Land driver when its undocumented transaction protocol is reproduced.
BTR.sys Driver File Properties (Image source: Checkpoint)
Microsoft Defender Driver Can Be Weaponized
BTR. sys is embedded within Microsoft Defender’s MpEngine. dll and is deployed when Defender needs to complete a remediation task after reboot, such as removing a file locked by the operating system.
