Threat Intelligence

Microsoft Defender's Own Driver Can Be Turned Into a Security-Killing Tool

The Hacker News · 22 Aug 2026
Key Takeaway Keep Windows systems fully updated and monitor vendor advisories closely, since even trusted built-in tools can potentially be abused to disable your security software.

Security researchers at Check Point have revealed a concerning technique that turns a trusted, digitally signed Microsoft Defender component into a weapon against the very systems it's meant to protect. The driver in question, called BTR.sys (Boot Time Removal Tool), is designed to remove malicious files during startup. However, researchers found it can be manipulated to perform arbitrary file and registry deletions at the deepest level of Windows, affecting systems from Windows 7 through the latest Windows 11 25H2.

What makes this technique particularly worrying is that it doesn't rely on a software vulnerability or malware smuggled onto the machine. Because BTR.sys is a genuine, Microsoft-signed driver already present on Windows systems, it can bypass typical security checks that look for suspicious or unauthorised code. This means attackers with sufficient access could potentially disable antivirus tools and other security software before the operating system fully loads, leaving a compromised machine with no active defences.

While this is a research disclosure rather than an active widespread attack, it highlights a broader lesson for businesses: even trusted, built-in software components can be misused by attackers who understand how to abuse legitimate functionality rather than break it. Organisations should stay alert for guidance from Microsoft on any mitigations or patches related to this issue.

Windows Security Microsoft Defender Endpoint Protection

Summarised by CISO AI from The Hacker News. We link back to every original so you can read it yourself.