Microsoft Defender's Own Driver Can Be Turned Into a Security-Killing Tool
Security researchers at Check Point have revealed a concerning technique that turns a trusted, digitally signed Microsoft Defender component into a weapon against the very systems it's meant to protect. The driver in question, called BTR.sys (Boot Time Removal Tool), is designed to remove malicious files during startup. However, researchers found it can be manipulated to perform arbitrary file and registry deletions at the deepest level of Windows, affecting systems from Windows 7 through the latest Windows 11 25H2.
What makes this technique particularly worrying is that it doesn't rely on a software vulnerability or malware smuggled onto the machine. Because BTR.sys is a genuine, Microsoft-signed driver already present on Windows systems, it can bypass typical security checks that look for suspicious or unauthorised code. This means attackers with sufficient access could potentially disable antivirus tools and other security software before the operating system fully loads, leaving a compromised machine with no active defences.
While this is a research disclosure rather than an active widespread attack, it highlights a broader lesson for businesses: even trusted, built-in software components can be misused by attackers who understand how to abuse legitimate functionality rather than break it. Organisations should stay alert for guidance from Microsoft on any mitigations or patches related to this issue.