Microsoft Defender Driver Exploited for Kernel-Level Attacks

Microsoft Defender Driver Exploited for Kernel-Level Attacks

First seen 20 Aug 2026, 21:12 UTC Research.CheckpointCybersecuritynewsgithub.comlearn.microsoft.com 90% similarity 64.5

Article Content

Browse articles
ThreatCluster

Research reveals that the Microsoft Defender Boot-Time Removal driver (BTR.sys) can be weaponized to execute arbitrary file and registry operations at the kernel level. This capability allows attackers with administrative privileges to disable endpoint security solutions without exploiting traditional vulnerabilities. The Check Point study highlights how this legitimate Microsoft-signed driver can be transformed into a tool for bypassing security measures. The research was initiated during an incident response investigation where legitimate Defender activity was misidentified as malicious. The findings raise concerns about the potential for similar abuses in other trusted components within Windows. No specific CVEs were identified, and the attack method does not rely on conventional exploitation techniques. This situation emphasizes the need for heightened scrutiny of trusted security components.

Key Points: • BTR.sys can be weaponized to perform kernel-level operations by attackers. • No traditional vulnerabilities or exploits are involved in this attack method. • The research highlights risks associated with trusted security components.

ThreatCluster AI How this analysis works

Timeline

2026-08-20
Research on BTR.sys published
Check Point reveals how the Microsoft Defender Boot-Time Removal driver can be repurposed for kernel-level attacks.
Research.Checkpoint
2026-08-20
Cybersecurity news coverage
Cybersecuritynews reports on the Check Point research, emphasizing the implications for endpoint security.
Cybersecuritynews

Community

Browse all →

Tracked Entities in This Story