BTR Reforged: Weaponizing Defender’s Remediation Driver as a Kernel Operation Primitive
Strategic summary
The report analyzes the Microsoft-signed Windows Defender Boot-Time Removal driver BTR.sys and shows how this legitimate remediation driver can be abused as a kernel operation primitive without exploits or memory corruption. The researchers reverse engineer the proprietary transaction format and introduce the tool BTR_CLI, which creates valid encrypted transactions to execute arbitrary file and registry operations from the kernel. This allows the driver to be used as an EDR/AV bypass technique that does not rely on typical BYOVD methods. The report warns that trusted security components can unintentionally expose powerful primitives and that similar patterns may exist in other signed remediation drivers.
Key findings
- The signed Microsoft driver BTR.sys can perform arbitrary file and registry operations from the kernel without vulnerabilities or exploits.
- The BTR_CLI tool creates valid encrypted transactions and demonstrates how the legitimate remediation component can become a universal kernel operation engine.
- BTR_CLI enables EDR/AV bypass using a trusted Windows built-in component and without typical BYOVD techniques.
- The research shows that trusted security infrastructure can unintentionally expose powerful primitives and that similar patterns may exist in other signed components.
- The discovery originated from an incident response investigation where suspicious telemetry was traced to legitimate Defender remediation with randomly named drivers.
Relevance for you
BTR.sys is a built-in Windows component that can be abused as a LOLDriver and is not covered by Microsoft's driver blocklist, offering a new kernel-operation primitive post-compromise.
Risk score
- cvss base
- 0.00
- kev bonus
- 0.00
- epss bonus
- 0.00
- poc bonus
- 15.00
- raw before weight
- 15.00
- industry weight
- 1.21
- freshness factor
- 0.50
- exploitability factor
- 1.00
- days old
- 25.00
- vendor mismatch penalty
- 0.00
- consensus penalty
- -3.00
Path: operational
Consensus check
The pipeline self-checks before delivery. These rules lowered the score:
-
TTP_SKIPPEDTTP mapping skipped (placeholder or aggregation article) −3
- Consensus penalty:
- −3.0
- Total penalty:
- −3.0