← Back to blog

Microsoft Defender Driver Exploited to Bypass Security at Boot

A legitimate Microsoft Defender driver can be abused to delete security software during system startup. No external drivers or exploits are needed, raising concerns for enterprise environments.

TL;DR

  • Check Point Research found a way to abuse Microsoft Defender's BTR.sys driver.
  • The attack works at boot time with kernel-level privileges.
  • No software flaws or third-party drivers are required.
  • Affects Windows 7 through Windows 11 25H2.
  • Organizations should monitor for unusual boot-time driver behavior.

In a surprising discovery, researchers at Check Point have revealed that Microsoft Defender’s own boot-time driver can be weaponized to carry out destructive actions before most security tools load. The BTR.sys driver, designed for remediation tasks, can be instructed to delete files or modify registry keys with high-level privileges.

This method does not rely on exploiting software bugs or loading unsigned drivers, making it particularly stealthy. Because the driver is digitally signed by Microsoft and already present on the system, traditional defenses may fail to detect its misuse. The vulnerability spans multiple Windows versions, including the latest Windows 11 25H2 builds.

How the Attack Works

  • The BTR.sys driver runs during the Windows boot process with kernel-mode access.
  • Attackers can manipulate the driver to perform unauthorized file deletions or registry changes.
  • No additional drivers or malicious code installations are required.
  • The technique bypasses user-mode security protections due to early execution timing.

Impact and Mitigation

  • Windows 7 through Windows 11 25H2 are potentially affected.
  • Enterprises using Microsoft Defender should audit boot-time driver activity.
  • Behavioral monitoring tools may help detect misuse of legitimate system drivers.
  • Organizations should apply future patches or guidance from Microsoft once available.

Sources

Sources

Security email updates

One digest email when we publish new security articles (TL;DR plus links to read more). Unsubscribe anytime from the message footer. See our Privacy Policy.

Microsoft Defender Driver Exploited to Bypass Security at Boot — Agent Breach Blog | Agent Breach