Skip to content
Microsoft Defender’s signed BTR.sys driver can erase security tools at boot

Microsoft Defender’s signed BTR.sys driver can erase security tools at boot

Feeds.4Sysops IT News August 21, 2026

A Microsoft-signed driver built into Defender can be repurposed to remove antivirus and EDR components before they start, giving attackers with administrator-level privileges a powerful boot-time evasion technique. Check Point Research says the approach works from Windows 7 through Windows 11 25H2, bypasses common driver-blocking controls, and is not currently linked to real-world attacks. Source

Extracted Entities

Tools (1)