Check Point Research disclosed that Microsoft Defender’s Boot-Time Removal driver, BTR.sys, can be repurposed as a Microsoft-signed kernel primitive for arbitrary file and registry operations, allowing attackers with administrator rights and SeLoadDriverPrivilege to tamper with protected security components during early startup. The researchers reverse engineered the driver’s undocumented transaction protocol, including its RC4-encrypted format and :changelist alternate data stream, and released the BTR_CLI proof-of-concept to generate valid transactions and stage the driver across Windows 7 through Windows 11 25H2.
The technique does not rely on a memory-corruption flaw or traditional bring-your-own-vulnerable-driver abuse, but instead uses a trusted built-in Windows component that is not covered by Microsoft’s vulnerable driver block rules or common LOLDrivers-style blocking approaches. Researchers said the boot-time execution window could let attackers delete or move files such as WdFilter.sys and MsMpEng.exe, or modify service-related registry keys before higher-level protections fully initialize; they reported no observed in-the-wild exploitation and recommended focusing on behavioral detection, monitoring ADS :changelist creation, unusual BTR.sys loads, suspicious service staging, BootClean.log artifacts, and tighter control of SeLoadDriverPrivilege.

Get the actors, campaigns, and ATT&CK mapping behind it.
6 events from the most recent confirmed update back to the earliest known activity.
Check Point Research published reverse-engineering research showing how Windows Defender's BTR.sys can be repurposed as a signed kernel-mode primitive for arbitrary file and registry operations. The report documented the RC4-encrypted transaction format, identified six supported action IDs, and said no in-the-wild abuse had been observed.
A public GitHub repository for BTR_CLI described an offensive proof-of-concept that weaponizes Microsoft's signed BTR.sys remediation driver. The repository included details on runtime and boot-time execution, anti-forensics, and Defender component removal demonstrations.
The BTR_CLI documentation states the technique was confirmed operational from Windows 7 through Windows 11 25H2. It anchors that validation as current as July 2026.
The BTR.sys abuse technique was reported to Microsoft's Security Response Center, according to the BTR_CLI project documentation. The report said the technique requires administrator rights and SeLoadDriverPrivilege.
Check Point researcher Jiří Vinopal presented the BTR Reforged technique in Las Vegas at Black Hat USA 2026 and DEF CON 34. The talks publicly demonstrated how Microsoft's signed BTR.sys remediation driver could be abused for arbitrary kernel-level file and registry operations.
Microsoft's Security Response Center determined the BTR.sys findings did not meet criteria for immediate servicing because the technique requires pre-existing administrative privileges, including SeLoadDriverPrivilege. The project documentation says no patch is planned.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
13 references tracked. Mallory keeps watching after this page renders.
malware.news
Open sourcecsoonline.com
Open sourceheise.de
Open sourcemkd-cirt.mk
Open sourceresearch.checkpoint.com
Open sourcegithub.com
Open sourcelearn.microsoft.com
Open sourceloldrivers.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.