Windows Defender’s own driver can leave systems defenseless
Summary
Researchers have discovered that Windows Defender's own Boot-Time Removal driver (BTR.sys) can be repurposed as a kernel-level operation engine. This technique allows attackers with existing privileges to perform arbitrary file and registry operations, and disable security controls without exploiting a traditional vulnerability or using the BYOVD model.
IFF Assessment
This research reveals a new method for attackers to leverage legitimate system components for malicious purposes, posing a significant threat to defenses.
Defender Context
Defenders should be aware that even trusted, Microsoft-signed drivers can be weaponized. While this attack requires pre-existing privileges and has not been observed in the wild, it highlights the importance of scrutinizing driver behavior and the potential for abuse of system functionalities.