BEGIN:VCALENDAR
VERSION:2.0
PRODID:-//pretalx//pretalx.com//hack-lu-2026//talk//YAUCQT
BEGIN:VTIMEZONE
TZID:Europe/Luxembourg
BEGIN:DAYLIGHT
DTSTART:20251021T000000
TZNAME:CEST
TZOFFSETFROM:+0200
TZOFFSETTO:+0200
END:DAYLIGHT
BEGIN:STANDARD
DTSTART:20251026T030000
RDATE:20261025T030000
TZNAME:CET
TZOFFSETFROM:+0200
TZOFFSETTO:+0100
END:STANDARD
BEGIN:DAYLIGHT
DTSTART:20260329T030000
RDATE:20270328T030000
TZNAME:CEST
TZOFFSETFROM:+0100
TZOFFSETTO:+0200
END:DAYLIGHT
END:VTIMEZONE
BEGIN:VEVENT
SUMMARY:BTR Reforged: Weaponizing Defender's Remediation Driver as a Kerne
 l Operation Primitive - Jiří Vinopal
DTSTART;TZID=Europe/Luxembourg:20261021T141500
DTEND;TZID=Europe/Luxembourg:20261021T144500
DTSTAMP:20261009T054059Z
UID:pretalx-hack-lu-2026-YAUCQT@pretalx.com
DESCRIPTION:What if a trusted security component could be repurposed into 
 an attacker-controlled kernel primitive? What if a signed Microsoft remedi
 ation driver could be instructed to execute arbitrary file and registry op
 erations from Ring 0—without exploits\, vulnerabilities\, or memory corr
 uption?\n\nIn this talk\, we present the first full reverse engineering of
  the Windows Defender Boot-Time Removal driver (BTR.sys) and its proprieta
 ry transaction format. We dissect its encrypted configuration mechanism\, 
 integrity validation logic\, and execution pipeline\, and demonstrate how 
 this legitimate remediation component can be transformed into a universal 
 kernel operation engine. We introduce BTR_CLI\, a research tool that const
 ructs valid encrypted transactions and safely exercises the driver’s fun
 ctionality to demonstrate its capabilities.\n\nFurthermore\, we demonstrat
 e how the BTR_CLI can be used as an EDR/AV bypass technique\, disarming se
 curity solutions while using a trusted Windows built-in\, Microsoft-signed
  driver\, thus not relying on typical BYOVD techniques.\n\nOur research re
 veals how trusted security infrastructure can unintentionally expose power
 ful primitives\, what this means for defenders\, and how similar patterns 
 may exist in other signed remediation components. This talk blends reverse
  engineering\, kernel internals\, and detection engineering into a practic
 al case study of when defensive technology becomes offensive capability.
LOCATION:Europe
URL:https://pretalx.com/hack-lu-2026/talk/YAUCQT/
END:VEVENT
END:VCALENDAR
