Microsoft Defender’s legitimate Boot-Time Removal (BTR.sys) driver can be repurposed to perform powerful kernel-level file and registry operations, potentially enabling attackers with administrative privileges to neutralize endpoint security protections. The Check Point research does not describe a conventional vulnerability or memory-corruption flaw; instead, it exposes how a trusted, Microsoft-signed remediation component can become a Living-off-the-Land […]
Read the original article: