#4
The Hacker News
general
August 21, 2026 at 15:52 UTC
Microsoft Defender's Own Driver Can Be Weaponized to Delete Security Software at Boot
By [email protected] (The Hacker News)
AI Summary
Check Point Research disclosed a technique abusing Microsoft Defender's legitimately signed boot-time driver BTR.sys (Boot Time Removal Tool) to perform arbitrary kernel-level file and registry deletions on Windows systems from Windows 7 through Windows 11 25H2. No external driver is required and no software vulnerability is exploited, meaning the technique is difficult to detect and block via conventional defenses.
Relevance score: 88.0/100
Sponsored
Protect Your Business
Expert cybersecurity solutions to safeguard your organization from evolving threats.
Get Protected →