Check Point Research fully reverse-engineered Windows Defender's Boot-Time Removal driver (BTR.sys) and showed that an administrator with SeLoadDriverPrivilege can stage it to execute arbitrary kernel-level file and registry deletions at next boot โ neutralising EDR and third-party security software during the window before Defender's user-mode protection starts. No software flaw is exploited and the driver is a required Windows component, so it cannot be added to Microsoft's vulnerable-driver blocklist without disabling Defender. Check Point found no evidence of in-the-wild abuse; the "BTR Reforged" work was presented at Black Hat USA 2026 and DEF CON 34 on 20โ21 August 2026. Defenders should monitor for manual staging of the driver's transaction files and restrict administrative privilege accordingly.