BTR.sys: Microsoft Defender’s Boot-Time Removal Tool Driver
BTR.sys is a legitimate signed driver used by Microsoft Defender to remove malware after a reboot. It is embedded in MpEngine.dll and…
BTR.sys is a legitimate signed driver used by Microsoft Defender to remove malware after a reboot. It is embedded in MpEngine.dll and…
msagent.sys is a signed Windows kernel-mode driver used by the latest CoolClient variant. It provides stealth by hiding processes, files, registry keys,…
AFD.sys is a Windows kernel driver that provides Winsock functionality. It contains the privilege escalation vulnerability CVE-2026-68820, which was exploited by Lazarus…