⌁ CyberSecurityBoardThreat Intel · CVEs · Products
Cyber News

Microsoft Defender’s Boot-Time Driver Can Be Abused to Delete Security Software

August 21, 2026

Check Point Research has disclosed a technique that abuses Microsoft Defender’s own legitimately signed boot-time remediation driver, BTR.sys, to perform arbitrary kernel-level file and registry operations on Windows systems from Windows 7 through Windows 11 25H2. The technique, dubbed ‘BTR Reforged,’ requires no software flaw and does not rely on importing a third-party driver. Because BTR.sys is a required Windows component, it cannot be added to Microsoft’s Vulnerable Driver Blocklist or blocked via Windows Defender Application Control without disrupting Defender itself.

Researcher Jiří Vinopal reverse-engineered the driver’s undocumented transaction protocol, discovering that configuration blobs are RC4-encrypted with a hard-coded 256-byte key present in every BTR.sys build since Windows 7. The proof-of-concept tool, BTR_CLI, extracts BTR.sys from Defender’s MpEngine.dll, installs it as a service via direct registry writes (bypassing the Service Control Manager and avoiding Event ID 7045), and triggers operations during the ‘golden window’ after the filesystem becomes writable but before Defender’s user-mode services start. This allows deletion of security binaries such as WdFilter.sys and MsMpEng.exe, even with Tamper Protection active.

Exploitation requires an administrator account with SeLoadDriverPrivilege. Check Point Research found no evidence of real-world abuse and emphasizes that this is an architectural trust boundary rather than a traditional vulnerability. Microsoft’s MSRC confirmed the findings do not meet criteria for immediate servicing. The research was presented at Black Hat USA 2026 and DEF CON 34, with BTR_CLI released on GitHub under the MIT license.

Indicators of compromise include specific Sysmon events (IDs 15, 12/13, 11, 23, 6) and the creation of a service key with Group ‘Boot Bus Extender’ without Event ID 7045. Recommended hardening includes restricting SeLoadDriverPrivilege. This research originated from an incident response investigation where suspicious telemetry was traced to legitimate Defender activity.

CVEs: CVE-2021-24092

Attack groups: FIN7

Malware: AvNeutralizer

Companies: Microsoft, Check Point Research, SentinelLabs

Products: Microsoft Defender, BTR.sys, Windows, Sysmon, Windows Defender Application Control

Events: Black Hat USA 2026, DEF CON 34