Skip to content
Auto-CTI
Back to all deep dives
CHECK POINT RESEARCH

BTR Reforged: Weaponizing Defender’s Remediation Driver as a Kernel Operation Primitive

MEDIUM Windows Defender BTR.sys LOLDriver

Strategic summary

The report analyzes the Microsoft-signed Windows Defender Boot-Time Removal driver BTR.sys and shows how this legitimate remediation driver can be abused as a kernel operation primitive without exploits or memory corruption. The researchers reverse engineer the proprietary transaction format and introduce the tool BTR_CLI, which creates valid encrypted transactions to execute arbitrary file and registry operations from the kernel. This allows the driver to be used as an EDR/AV bypass technique that does not rely on typical BYOVD methods. The report warns that trusted security components can unintentionally expose powerful primitives and that similar patterns may exist in other signed remediation drivers.

Key findings

  • The signed Microsoft driver BTR.sys can perform arbitrary file and registry operations from the kernel without vulnerabilities or exploits.
  • The BTR_CLI tool creates valid encrypted transactions and demonstrates how the legitimate remediation component can become a universal kernel operation engine.
  • BTR_CLI enables EDR/AV bypass using a trusted Windows built-in component and without typical BYOVD techniques.
  • The research shows that trusted security infrastructure can unintentionally expose powerful primitives and that similar patterns may exist in other signed components.
  • The discovery originated from an incident response investigation where suspicious telemetry was traced to legitimate Defender remediation with randomly named drivers.

Relevance for you

BTR.sys is a built-in Windows component that can be abused as a LOLDriver and is not covered by Microsoft's driver blocklist, offering a new kernel-operation primitive post-compromise.

Risk score

6
cvss base
0.00
kev bonus
0.00
epss bonus
0.00
poc bonus
15.00
raw before weight
15.00
industry weight
1.21
freshness factor
0.50
exploitability factor
1.00
days old
25.00
vendor mismatch penalty
0.00
consensus penalty
-3.00

Path: operational

Consensus check

The pipeline self-checks before delivery. These rules lowered the score:

  • TTP_SKIPPED TTP mapping skipped (placeholder or aggregation article) −3
Consensus penalty:
−3.0
Total penalty:
−3.0
ESC