Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
News Microsoft Defender's Own Driver Can Be Weaponized to Delete Security Software at Boot
The Hacker News
4 hours from now

Microsoft Defender's Own Driver Can Be Weaponized to Delete Security Software at Boot

By info@thehackernews.com (The Hacker News)

Check Point Research has disclosed a technique that uses Microsoft Defender's own legitimately signed boot-time remediation driver to perform arbitrary kernel-level file and registry operations on Windows systems ranging from Windows 7 through Windows 11 25H2, with no software flaw exploited and no driver imported from outside the machine. The driver, BTR.sys (Boot Time Removal Tool), is a

More from The Hacker News

Leaving Threaticon

This link opens an external site that isn't part of the platform.