Diamond Member ThaHaka 0 Posted August 21 Diamond Member Share Posted August 21 This is the hidden content, please Sign In or Sign Up Check Point Research has disclosed a technique that uses This is the hidden content, please Sign In or Sign Up Defender's own legitimately signed boot-time remediation driver to perform arbitrary kernel-level file and registry operations on Windows systems ranging from Windows 7 through Windows 11 25H2, with no software flaw exploited and no driver imported from outside the machine. The driver, BTR.sys (Boot Time Removal Tool), is a This is the hidden content, please Sign In or Sign Up 0 Quote Link to comment https://hopzone.eu/forums/topic/326411-h4ckn3wsmicrosoft-defenders-own-driver-can-be-weaponized-to-delete-security-software-at-boot/ Share on other sites More sharing options...
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.