Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
20 distinct techniques documented for this family, organized by ATT&CK tactic.
Драјверот може да: брише registry keys и registry values; запишува нови registry values од кој било тип.
Драјверот се инсталира како сервис преку директно запишување во HKLM регистарот , со користење на: Type=1 Start=1 Group="Boot Bus Extender" Овој метод целосно го заобиколува Service Control Manager и не создава запис Windows Event ID 7045 (Service Installed) .
Once loaded, BTR.sys executes operations from Ring 0, allowing it to delete or move files, and modify registry entries.
Драјверот се инсталира како сервис преку директно запишување во HKLM регистарот , со користење на: Type=1 Start=1 Group="Boot Bus Extender" Овој метод целосно го заобиколува Service Control Manager и не создава запис Windows Event ID 7045 (Service Installed) .
Вториот режим на активирање ги закажува овие операции за следното рестартирање . Драјверот потоа се извршува во она што Vinopal го нарекува „golden window“
Boot Execution (trigger boot): Configures the service with Start=1 (System) and Group Boot Bus Extender to execute during the early boot phase, bypassing active EDR/AV protections.
Service creation & triggering - direct HKLM registry writes ... bypass the SCM, so no Event ID 7045 is generated.
Anti-forensics : BTR_CLI injecte automatiquement une Action 1 ciblant \SystemRoot\Temp\BootClean.log pour supprimer le log du driver avant déchargement
it exposes how a trusted, Microsoft-signed remediation component can become a Living-off-the-Land driver when its undocumented transaction protocol is reproduced.
Драјверот може да: брише registry keys и registry values; запишува нови registry values од кој било тип.
Action 3: Move / Quarantine Structure: [Flags] [Source Path] [Dest Path] Effect: Moves a file. Weaponization: If Dest Path is empty, this acts as a Delete operation. If Dest Path is valid, this allows Arbitrary File Write/Move (e.g., dropping a malicious DLL into System32).
Ова му овозможува на BTR.sys физички да ги отстрани безбедносните бинарни датотеки, како WdFilter.sys и MsMpEng.exe , пред тие да можат да се заштитат од бришење. Во демонстрација во живо ... истражувачите покажале како BTR_CLI го брише целиот Defender stack ... иако била активна Tamper Protection .
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A proof-of-concept tool that extracts Defender's embedded BTR.sys driver, builds valid encrypted transactions, installs the driver via direct registry writes, and uses it to perform kernel-level file and registry operations, including disabling or deleting Defender components.
A proof-of-concept research/red-team tool that extracts or embeds BTR.sys, builds valid encrypted transaction payloads, stages them via ADS, and triggers the driver to execute chained kernel-level file and registry operations.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.