Skip to content

Security2 publishersIndependently confirmed3 min readPublished Updated

Defender's own boot driver is a kernel delete primitive, and Microsoft is not servicing it

Check Point's BTR Reforged turns a required Defender component into Ring 0 file and registry deletion on Windows 7 through 11 25H2. It cannot be blocklisted, so detection is the only lever left.

The Watch · Security desk

How we use AISend a correction

What happened

  • Check Point Research showed Defender's own signed boot-time remediation driver performing arbitrary kernel file and registry operations on Windows 7 through Windows 11 25H2.
  • The proof-of-concept registers the driver through direct HKLM writes, bypassing the Service Control Manager and producing no Event ID 7045.
  • MSRC told Check Point the findings do not meet the bar for immediate servicing because the technique needs pre-existing admin rights.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • constraint The two levers defenders normally pull against signed driver abuse, the Vulnerable Driver Blocklist and WDAC, are unavailable here without breaking Defender's own post-reboot cleanup.
  • exposure Because the deletions are attributed to PID 4, any organisation whose hunting depends on process lineage or service-install events is blind to this by construction.
  • decision With no patch expected, the remaining choice for security teams is which artefacts to alert on, and how much boot-time registry noise they are willing to triage.
  • precedent Documenting a required, unblocklistable component as a Ring 0 delete primitive weakens the blocklist economics that made BYOVD manageable.

Tamper Protection defends a Defender that is running. The technique never fights it. BTR_CLI registers the driver with Start=1 in the "Boot Bus Extender" group [5], which places it in the boot order ahead of the software it is told to remove, and the queued operations run in the interval after the filesystem becomes writable but before Defender's user-mode services start, which Vinopal calls the golden window [7]. WdFilter.sys and MsMpEng.exe are deleted before they exist as processes capable of locking themselves [7]. The Black Hat demonstration against a fully updated Windows 11 25H2 host with Tamper Protection active [8] is the arithmetic of that ordering, not a defeat of the protection's logic.

The other durable detail is the key. Every configuration blob handed to BTR.sys is RC4-encrypted with a 256-byte key sitting in the .rdata section of every build shipped since Windows 7, and Check Point verified it unchanged across 18 distinct 64-bit versions [4]. Zero rotations in 18 sampled builds [15] cuts both ways. It means a tool written once keeps working across a decade of Windows, and it also means the transaction format is a stable artifact defenders can write signatures against. Rotating the key per build would raise the cost of maintaining an offline toolchain, though the key ships inside the binary on every machine that has Defender, so anyone who can read MpEngine.dll can read the key [3][4].

Microsoft's position is that this is not a vulnerability but an architectural trust boundary crossed by an attacker who already holds administrative privileges, and MSRC told Check Point the findings do not meet the criteria for immediate servicing because the technique depends on SeLoadDriverPrivilege [11][9]. That is a consistent line. It is also worth noting what the same driver got in February 2021, when SentinelLabs' Kasif Dekel disclosed CVE-2021-24092, an arbitrary file overwrite reachable by a local non-administrator through a hard link at the driver's log path [14]. Five years and six months separate that fix from this disclosure [16]. The boundary moved from "non-admin can abuse BTR.sys" to "admin can abuse BTR.sys," and only one of those buys a patch.

So the defensive surface is narrow and specific. Service installation via direct HKLM writes skips the Service Control Manager and produces no Event ID 7045 [5], and execution is attributed to the System process at PID 4 [6], which removes the two artefacts most hunting content assumes: a service-install event and a suspicious parent. What remains is the registry write itself, the shape of the encrypted transaction, and the deletion of Defender binaries by PID 4 during boot. Check Point says it saw no evidence of real-world abuse in its samples and telemetry [2], which is the only reason that detection work can be done before it is needed rather than during an incident. BTR_CLI has been public since August 20, 2026 [13].

What to watch

  • Whether Microsoft revisits BTR.sys handling, for example rotating the hard-coded key per build or validating transaction origin, after declining immediate servicing.
  • Whether EDR vendors ship detections for boot-start service registry writes and BTR transaction blobs that survive System process attribution.
  • Whether any in-the-wild use appears now that BTR_CLI is public, which would end Check Point's no-observed-abuse position.

Clarity's read

What the record supports and how the coverage leans. The claims behind it follow.

Reality

Evidence60
Adoption8
Hype gap+10
Incentives
Insufficient
Confidence62
Why these scores

Claim ledger

Ranked by verification strength, evidence, and original report placement.

  1. [1]

    Check Point Research disclosed a technique that uses Microsoft Defender's legitimately signed boot-time remediation driver to perform arbitrary kernel-level file and registry operations on Windows systems from Windows 7 through Windows 11 25H2, with no software flaw exploited and no driver imported from outside the machine.

    ReportedSupportedSource: Check Point Research, via The Hacker News2 sources— create a free account to open themView cited source
  2. [2]

    Check Point Research said that across all collected samples and telemetry sources it did not observe evidence of real-world abuse of BTR.sys in the manner demonstrated, suggesting the technique is currently unknown or unused by threat actors and that proactive detection engineering is feasible before weaponization appears in the wild.

    ReportedSupportedSource: Check Point Research2 sources— create a free account to open themView cited source
  3. [3]

    BTR.sys is embedded in Defender's MpEngine.dll as the BOOTTIMETOOL resource and is deployed when Defender must finish removing malware after a reboot, deleting files or registry entries that were locked while Windows was running. BTR_CLI locates MpEngine.dll under Defender's Definition Updates and extracts the embedded BTR.sys binary.

Sources

2 independent publishers whose own reporting we read for this story.

  1. scworld.com

    1 article · August 21, 2026

    Researchers find way to weaponize Windows Defender's own driver
  2. thehackernews.com

    2 articles · August 22, 2026

    Microsoft Defender's Own Driver Can Be Weaponized to Delete Security Software at Boot

Share your take

Let Clarity write the post for you.

Signed-in readers get a short post drafted on this story in the register they choose — narrative, analytical, or a direct position — editable to the last word before it goes anywhere. The share buttons at the top of this story work without an account.

Topics and entities

Follow any of these and your For You feed starts watching them — no settings page required.

Topics

Entities

Loading related stories