Microsoft Defender's BTR.sys Driver Abused to Kill Security Tools at Boot
Check Point Research revealed that Microsoft Defender's legitimate kernel-level driver (BTR.sys) can be weaponized by an attacker with administrator privileges to delete security software — including Defender itself — before user-mode protections are active during system boot. This is not a traditional software vulnerability but an architectural trust boundary abuse, meaning no patch will immediately resolve the risk. The technique highlights a dangerous assumption: that trusted, signed system components are inherently safe from misuse by privileged insiders or compromised accounts. This matters because it effectively allows an attacker to blind an endpoint's defenses at the kernel level, leaving the system exposed for subsequent payloads. Organizations relying solely on endpoint security software as a last line of defense must reconsider their layered security assumptions.
Tactical Insight
Immediate actions
- Enforce strict least-privilege policies to ensure no unauthorized users or processes hold administrator-level rights that could invoke kernel drivers.
- Enable Windows Credential Guard and Secure Boot to reduce the attack surface available to kernel-level manipulation.
Long-term improvements
- Implement a defense-in-depth strategy with multiple overlapping security controls so that disabling one endpoint agent does not leave systems fully unprotected.
- Deploy a centralized SIEM or XDR platform to detect anomalous driver loading or unexpected deletion of security software binaries during boot sequences.
- Establish privileged access workstations (PAWs) and tiered administration models to limit which accounts can interact with kernel-level components.
Detection measures
- Monitor for unexpected changes to security software directories or registry keys associated with endpoint protection tools, particularly during pre-boot or early-boot phases.
- Alert on the unusual invocation of BTR.sys or similar trusted drivers outside of their expected operational context.
- Regularly audit administrator account activity and correlate driver usage events with change management records to detect unauthorized operations.