Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
15 distinct techniques documented for this family, organized by ATT&CK tactic.
The six kernel primitives BTR.sys exposes are all available: ... 4 Delete Registry Key 5 Delete Registry Value 6 Set Registry Value Creates parent key path if missing.
Service creation & triggering - direct HKLM registry writes ( Type=1, Start=1, ErrorControl=0, Group="Boot Bus Extender" ) bypass the SCM, so no Event ID 7045 is generated. Triggered immediately via NtLoadDriver ( -trigger now ) or scheduled for the next boot
the undocumented transaction protocol spoken by BTR.sys - the Microsoft-signed kernel driver that Windows Defender uses to remediate malware at boot time - and shows how that protocol can be driven from user-mode to obtain a permanent, built-in, WDAC-immune Ring-0 file & registry primitive on every modern Windows install.
Service creation & triggering - direct HKLM registry writes ( Type=1, Start=1, ErrorControl=0, Group="Boot Bus Extender" ) bypass the SCM, so no Event ID 7045 is generated. Triggered immediately via NtLoadDriver ( -trigger now ) or scheduled for the next boot
Triggered immediately via NtLoadDriver ( -trigger now ) or scheduled for the next boot inside the "Golden Window" - the interval where the filesystem is writable but Defender's user-mode services haven't started ( -trigger boot ).
It is dropped to disk (with a randomized filename matching [a-z]{8}.sys , e.g., mzqnjtaq.sys ) only when a remediation action requires a reboot... accompanied by the following registry entries... At first glance, several characteristics resembled attacker tradecraft: A randomly named driver dropped shortly before reboot Creation of a transient service entry for loading it
Service creation & triggering - direct HKLM registry writes ... bypass the SCM, so no Event ID 7045 is generated.
Action 1: Delete File Structure: [Path] Effect: Kernel-level deletion. Bypasses exclusive file locks. | The BTR_CLI tool automatically injects an Action 1 item at the start of the transaction list targeting BootClean.log . Result: The driver creates the log, performs the user’s action, and then deletes its own log file before unloading.
This classification establishes BTR.sys as a potent “Living-off-the-Land” driver (LOLDriver).
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A legitimate Microsoft-signed Windows Defender remediation driver that can be repurposed to perform arbitrary kernel-mode file and registry operations via encrypted transaction blobs, enabling EDR/AV bypass, tamper-protection bypass, file deletion/move, and registry modification without exploiting a vulnerability.
A Microsoft-signed Windows Defender remediation driver that can be repurposed to perform arbitrary kernel-mode file and registry operations via encrypted transaction blobs, enabling EDR/AV bypass, tamper-protection bypass, file deletion/move, and registry modification without exploiting a vulnerability.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.