Security2 publishersIndependently confirmed3 min readPublished Updated
Defender's own boot driver is a kernel delete primitive, and Microsoft is not servicing it
Check Point's BTR Reforged turns a required Defender component into Ring 0 file and registry deletion on Windows 7 through 11 25H2. It cannot be blocklisted, so detection is the only lever left.
The Watch · Security desk
What happened
- Check Point Research showed Defender's own signed boot-time remediation driver performing arbitrary kernel file and registry operations on Windows 7 through Windows 11 25H2.
- The proof-of-concept registers the driver through direct HKLM writes, bypassing the Service Control Manager and producing no Event ID 7045.
- MSRC told Check Point the findings do not meet the bar for immediate servicing because the technique needs pre-existing admin rights.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- constraint The two levers defenders normally pull against signed driver abuse, the Vulnerable Driver Blocklist and WDAC, are unavailable here without breaking Defender's own post-reboot cleanup.
- exposure Because the deletions are attributed to PID 4, any organisation whose hunting depends on process lineage or service-install events is blind to this by construction.
- decision With no patch expected, the remaining choice for security teams is which artefacts to alert on, and how much boot-time registry noise they are willing to triage.
- precedent Documenting a required, unblocklistable component as a Ring 0 delete primitive weakens the blocklist economics that made BYOVD manageable.
Tamper Protection defends a Defender that is running. The technique never fights it. BTR_CLI registers the driver with Start=1 in the "Boot Bus Extender" group [5], which places it in the boot order ahead of the software it is told to remove, and the queued operations run in the interval after the filesystem becomes writable but before Defender's user-mode services start, which Vinopal calls the golden window [7]. WdFilter.sys and MsMpEng.exe are deleted before they exist as processes capable of locking themselves [7]. The Black Hat demonstration against a fully updated Windows 11 25H2 host with Tamper Protection active [8] is the arithmetic of that ordering, not a defeat of the protection's logic.
The other durable detail is the key. Every configuration blob handed to BTR.sys is RC4-encrypted with a 256-byte key sitting in the .rdata section of every build shipped since Windows 7, and Check Point verified it unchanged across 18 distinct 64-bit versions [4]. Zero rotations in 18 sampled builds [15] cuts both ways. It means a tool written once keeps working across a decade of Windows, and it also means the transaction format is a stable artifact defenders can write signatures against. Rotating the key per build would raise the cost of maintaining an offline toolchain, though the key ships inside the binary on every machine that has Defender, so anyone who can read MpEngine.dll can read the key [3][4].
Microsoft's position is that this is not a vulnerability but an architectural trust boundary crossed by an attacker who already holds administrative privileges, and MSRC told Check Point the findings do not meet the criteria for immediate servicing because the technique depends on SeLoadDriverPrivilege [11][9]. That is a consistent line. It is also worth noting what the same driver got in February 2021, when SentinelLabs' Kasif Dekel disclosed CVE-2021-24092, an arbitrary file overwrite reachable by a local non-administrator through a hard link at the driver's log path [14]. Five years and six months separate that fix from this disclosure [16]. The boundary moved from "non-admin can abuse BTR.sys" to "admin can abuse BTR.sys," and only one of those buys a patch.
So the defensive surface is narrow and specific. Service installation via direct HKLM writes skips the Service Control Manager and produces no Event ID 7045 [5], and execution is attributed to the System process at PID 4 [6], which removes the two artefacts most hunting content assumes: a service-install event and a suspicious parent. What remains is the registry write itself, the shape of the encrypted transaction, and the deletion of Defender binaries by PID 4 during boot. Check Point says it saw no evidence of real-world abuse in its samples and telemetry [2], which is the only reason that detection work can be done before it is needed rather than during an incident. BTR_CLI has been public since August 20, 2026 [13].
What to watch
- Whether Microsoft revisits BTR.sys handling, for example rotating the hard-coded key per build or validating transaction origin, after declining immediate servicing.
- Whether EDR vendors ship detections for boot-start service registry writes and BTR transaction blobs that survive System process attribution.
- Whether any in-the-wild use appears now that BTR_CLI is public, which would end Check Point's no-observed-abuse position.
Clarity's read
What the record supports and how the coverage leans. The claims behind it follow.
Reality
- Evidence60
- Adoption8
- Hype gap+10
- Incentives
- Insufficient
- Confidence62
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
Check Point Research disclosed a technique that uses Microsoft Defender's legitimately signed boot-time remediation driver to perform arbitrary kernel-level file and registry operations on Windows systems from Windows 7 through Windows 11 25H2, with no software flaw exploited and no driver imported from outside the machine.
ReportedSupportedSource: Check Point Research, via The Hacker News2 sources— create a free account to open themView cited source - [2]
Check Point Research said that across all collected samples and telemetry sources it did not observe evidence of real-world abuse of BTR.sys in the manner demonstrated, suggesting the technique is currently unknown or unused by threat actors and that proactive detection engineering is feasible before weaponization appears in the wild.
ReportedSupportedSource: Check Point Research2 sources— create a free account to open themView cited source - [3]
BTR.sys is embedded in Defender's MpEngine.dll as the BOOTTIMETOOL resource and is deployed when Defender must finish removing malware after a reboot, deleting files or registry entries that were locked while Windows was running. BTR_CLI locates MpEngine.dll under Defender's Definition Updates and extracts the embedded BTR.sys binary.
- [4]
Every configuration blob passed to BTR.sys is RC4-encrypted with a 256-byte key hard-coded in the .rdata section of every BTR.sys build shipped since Windows 7, verified unchanged across 18 unique 64-bit versions.
- [5]
BTR_CLI installs the driver as a service via direct HKLM registry writes using Type=1, Start=1 and Group="Boot Bus Extender", a method that bypasses the Service Control Manager entirely and generates no Windows Event ID 7045 (Service Installed) entry.
- [6]
When loaded, BTR.sys executes the queued operations from Ring 0, attributed in telemetry to the System process (PID 4), and can delete locked files and directories, move files to unconstrained paths including System32\drivers, delete registry keys and values, and write new registry values of any type.
- [7]
A second trigger mode schedules the operations for the next reboot, so the driver executes during what Vinopal calls the "golden window", the interval after the filesystem becomes writable but before Defender's user-mode services have started, allowing BTR.sys to physically remove security binaries such as WdFilter.sys and MsMpEng.exe before they can lock themselves.
- [8]
A live demonstration at Black Hat showed BTR_CLI deleting the entire Defender stack from a fully updated Windows 11 25H2 machine with Tamper Protection active.
- [9]
Exploitation requires an administrator account with SeLoadDriverPrivilege, which BTR_CLI auto-enables for accounts that already hold it.
- [10]
Unlike bring your own vulnerable driver attacks, which depend on known-vulnerable third-party signed drivers that can be added to blocklists, the BTR Reforged technique uses a driver built into every Windows installation from Windows 7 onward.
- [11]
Check Point's paper says the issue is not a vulnerability in the traditional sense but an architectural trust boundary that can be crossed if an attacker already has administrative privileges, and that following responsible disclosure MSRC confirmed the findings do not meet the criteria for immediate servicing because the technique relies on pre-existing administrative privileges (SeLoadDriverPrivilege).
ReportedSupportedSource: Check Point Research paper, citing MSRC2 sources— create a free account to open themView cited source - [12]
BTR.sys (Boot Time Removal Tool) is a required Windows component, which means it cannot be added to Microsoft's Vulnerable Driver Blocklist or blocked via Windows Defender Application Control without disrupting Defender itself.
- [13]
Jiri Vinopal, a threat researcher and reverse engineer at Check Point Research, presented the findings as a main-stage briefing at Black Hat USA 2026 and DEF CON 34 in Las Vegas and published the research paper alongside a proof-of-concept tool, BTR_CLI, on August 20, 2026.
- [14]
In February 2021, SentinelLabs researcher Kasif Dekel disclosed CVE-2021-24092, a privilege escalation vulnerability in the same driver that allowed a local non-administrator to overwrite arbitrary files by placing a hard link at the driver's log path.
- [15]
Across the 18 unique 64-bit BTR.sys builds Check Point examined, the hard-coded RC4 key changed zero times.
- [16]
Five years and six months separate the February 2021 disclosure of CVE-2021-24092 in BTR.sys from the August 20, 2026 publication of the BTR Reforged research and BTR_CLI.
- [17]
Vinopal's GitHub repository for BTR_CLI states that "No patch is planned", a characterization Microsoft has not confirmed publicly.
Sources
2 independent publishers whose own reporting we read for this story.
- scworld.comResearchers find way to weaponize Windows Defender's own driver
1 article · August 21, 2026
- thehackernews.comMicrosoft Defender's Own Driver Can Be Weaponized to Delete Security Software at Boot
2 articles · August 22, 2026
Topics and entities
Follow any of these and your For You feed starts watching them — no settings page required.
Topics
- EDR and antivirus tamperingFollow
- Windows kernel driversFollow
- Bring Your Own Vulnerable DriverFollow
Entities
- Check Point ResearchFollow
- MicrosoftFollow
- BTR.sysFollow
- Kasif DekelFollow
- Microsoft Security Response CenterFollow
- Black Hat USAFollow
- SentinelLabsFollow
- Microsoft DefenderFollow
- BTR_CLIFollow
- Jiri VinopalFollow
- CVE-2021-24092Follow