#BTRsys
📢 BTR Reforged : le driver de remédiation Windows Defender transformé en primitive noyau offensive

Cet article présente la première rétro-ingénierie complète du driver BTR.sys (Windows Defender Boot-Time Removal), un composant…

🟢 vérification factuelle haute
#WindowsDefender #BTRSys #Cyberveille
BTR Reforged : le driver de remédiation Windows Defender transformé en primitive noyau offensive
Cet article présente la première rétro-ingénierie complète du driver BTR.sys (Windows Defender Boot-Time Removal), un composant légitime signé Microsoft embarqué dans MpEngine.dll. L'analyse a débuté lors d'une investigation de réponse à incident où le driver avait été initialement confondu avec un artefact malveillant en raison de ses caractéristiques inhabituelles.
cyberveille.ch
August 22, 2026 at 6:30 PM
Check Point found Microsoft Defender's signed BTR.sys driver can be abused at boot to delete security software and alter registry keys on Windows 7 to 11 25H2. #BTRsys #MicrosoftDefender #CheckPointResearch
Microsoft Defender's Own Driver Can Be Weaponized to Delete Security Software at Boot
Check Point Research revealed that Microsoft Defender’s legitimately signed BTR.sys boot-time remediation driver can be abused for arbitrary kernel-level file and registry operations on Windows from Windows 7 through Windows 11 25H2. The technique, demonstrated with the BTR_CLI proof-of-concept, can remove security binaries in a “golden window” after reboot, while Check...
www.hendryadrian.com
August 22, 2026 at 5:30 AM
Reverse engineering of Windows Defender BTR.sys shows its encrypted boot-time transaction format can be abused for arbitrary file and registry operations from Ring 0, enabling EDR bypass and Defender neutralization. #BTRsys #WindowsDefender #Ring0
BTR Reforged: Weaponizing Defender’s Remediation Driver as a Kernel Operation Primitive
This research reverse engineers Windows Defender’s BTR.sys boot-time remediation driver and shows how its encrypted transaction format can be abused to perform arbitrary file and registry operations from Ring 0. The paper also introduces BTR_CLI, demonstrates EDR/AV bypass and boot-time neutralization against Microsoft Defender, and highlights the defensive implications of a signed built-in LOLDriver. #BTR.sys #BTR_CLI #MicrosoftDefender #MsMpEng.exe #WdFilter.sys #WdBoot.sys #WdNisDrv.sys #Mimikatz #mimidrv.sys #MSRC
www.hendryadrian.com
August 20, 2026 at 2:00 PM