
Windows Defender's Boot Driver Could Be Weaponized to Wipe Security Tools at Startup
Check Point Research disclosed a technique that abuses Microsoft Defender’s built-in boot-time removal driver, BTR.sys, to perform kernel-level file and registry operations and potentially delete Defender components during boot. The driver is embedded in Defender and can be triggered with a PoC tool (BTR_CLI); it requires administrative SeLoadDriverPrivilege, but there is no evidence of real-world abuse yet. This isn’t a traditional software vulnerability but an architectural trust boundary that could be exploited, and Microsoft notes it doesn’t require immediate servicing. Defenses include restricting SeLoadDriverPrivilege and monitoring for specific Sysmon/Windows events, since BTR.sys is hard to blocklist without disrupting Defender.