Plan
active
Microsoft Defender's BTR.sys Driver Abused to Delete Security Tools at Boot
- Engineer — Learn: No exploitable flaw and no patch exists — this is abuse of a legitimately signed Defender component, so there’s nothing to patch; understand the technique and evaluate whether existing attack surface reduction or kernel driver allow-listing policies limit BTR.sys invocation outside Defender’s normal use.
- SOC/IR — Plan: Novel boot-time EDR-disablement technique worth building detections for: plan to hunt for anomalous BTR.sys loading events or unexpected security product file/registry removal at boot, and check whether your EDR vendor provides detection coverage for this abuse pattern.
- Leader — Learn: Research disclosure with no active exploitation signals; relevant background if stakeholders ask about Defender’s reliability as a security control, but no leadership action is required at this time.
This entry was curated and judged by AI (Claude) with automated enrichment
(CISA KEV / EPSS / public PoC). Verify against the original source before
acting. Found a bad verdict?
Report it —
confirmed errors go to the corrections log.