Home ยท Wiki ยท Incidents & Campaigns
type: incident ยท created: 2026-08-24 ยท updated: 2026-08-24 ยท tags: ยท confidence: high ยท severity: high ยท affected_sectors: ยท au_impact: false

Check Point Research fully reverse-engineered Windows Defender's Boot-Time Removal driver (BTR.sys) and showed that an administrator with SeLoadDriverPrivilege can stage it to execute arbitrary kernel-level file and registry deletions at next boot โ€” neutralising EDR and third-party security software during the window before Defender's user-mode protection starts. No software flaw is exploited and the driver is a required Windows component, so it cannot be added to Microsoft's vulnerable-driver blocklist without disabling Defender. Check Point found no evidence of in-the-wild abuse; the "BTR Reforged" work was presented at Black Hat USA 2026 and DEF CON 34 on 20โ€“21 August 2026. Defenders should monitor for manual staging of the driver's transaction files and restrict administrative privilege accordingly.

Sources