BTR Reforged: Weaponizing Defender's Remediation Driver as a Kernel Operation Primitive
What if a trusted security component could be repurposed into an attacker-controlled kernel primitive? What if a signed Microsoft remediation driver could be instructed to execute arbitrary file and registry operations from Ring 0—without exploits, vulnerabilities, or memory corruption?
In this talk, we present the first full reverse engineering of the Windows Defender Boot-Time Removal driver (BTR.sys) and its proprietary transaction format. We dissect its encrypted configuration mechanism, integrity validation logic, and execution pipeline, and demonstrate how this legitimate remediation component can be transformed into a universal kernel operation engine. We introduce BTR_CLI, a research tool that constructs valid encrypted transactions and safely exercises the driver’s functionality to demonstrate its capabilities.
Furthermore, we demonstrate how the BTR_CLI can be used as an EDR/AV bypass technique, disarming security solutions while using a trusted Windows built-in, Microsoft-signed driver, thus not relying on typical BYOVD techniques.
Our research reveals how trusted security infrastructure can unintentionally expose powerful primitives, what this means for defenders, and how similar patterns may exist in other signed remediation components. This talk blends reverse engineering, kernel internals, and detection engineering into a practical case study of when defensive technology becomes offensive capability.
This talk presents the first complete reverse engineering and weaponization of BTR.sys, the Windows Defender Boot-Time Removal driver. We begin by dissecting the driver's fully undocumented, RC4-encrypted transaction protocol — recovering the hardcoded cryptographic key, custom integrity validation scheme, and proprietary binary transaction structure that has remained unchanged across every Windows version from 7 through 11 25H2.
We then demonstrate how this legitimate, Microsoft-signed remediation component can be transformed into an attacker-controlled kernel operation primitive capable of arbitrary Ring-0 file and registry manipulation. We introduce BTR_CLI, an open source research tool that constructs valid encrypted transactions and exercises the driver's full capability set across all six Action IDs.
The talk concludes with the Golden Window technique — exploiting the Windows boot phase architecture to execute the primitive after filesystem initialization but before EDR and AV user-mode services can start or lock files — achieving complete security stack neutralization on a fully updated Windows 11 25H2 system without exploits, vulnerabilities, or memory corruption. Detection engineering and behavioral hunting strategies are provided for defenders.
Jiří Vinopal is a security researcher, malware researcher, and reverse engineer at Check Point Research, focused on advanced cyber threats, kernel internals, and the hidden mechanics of undocumented system components. His work spans uncovering novel attack primitives, reconstructing proprietary protocols from binary analysis alone, and deep-diving into both sophisticated malware families and trusted platform components. When he's not buried in disassembly, he actively shares his knowledge and passion for reverse engineering across his X account, YouTube channel, and blog — delivering tips, tricks, and technical insights to fellow enthusiasts and the broader security community.