Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

BTR Reforged: Weaponizing Defender’s Remediation Driver as a Kernel Operation Primitive

0
Medium
Vulnerabilitywindows
Published: 08/20/2026 (08/20/2026, 13:07:13 UTC)
Source: Check Point Research

Description

Research by: Jiří Vinopal ( @vinopaljiri ) Abstract What if a trusted security component could be repurposed into an attacker-controlled kernel primitive? What if a signed Microsoft remediation driver could be instructed to execute arbitrary file and registry operations from Ring 0 – without exploits, vulnerabilities, or memory corruption? In this publication, we present the first full reverse engineering of the Windows Defender Boot-Time Removal driver ( BTR.sys ) and its proprietary transaction format. We dissect its encrypted configuration mechanism, integrity validation logic, and execution pipeline, and demonstrate how this legitimate remediation component can be transformed into a universal kernel operation engine. We introduce BTR_CLI , a research tool that constructs valid encrypted transactions and safely exercises the driver’s functionality to demonstrate its capabilities. Furthermore, we demonstrate how BTR_CLI can be used as an EDR/AV bypass technique, disarming security solutions while using a trusted Windows built-in , Microsoft-signed driver, thus not relying on typical BYOVD techniques. Our research reveals how trusted security infrastructure can unintentionally expose powerful primitives, what this means for defenders, and how similar patterns may exist in other signed remediation components. This work blends reverse engineering, kernel internals, and detection engineering into a practical case study of when defensive technology becomes offensive capability . Introduction This research originated during an incident response investigation involving a compromised system, where certain endpoint telemetry appeared suspicious but was ultimately traced back to legitimate Windows Defender remediation activity. During analysis, a driver (internally identified as BTR.sys ) appeared on disk under System32\drivers with a randomized filename and a corresponding randomized service name ( HKLM\SYSTEM\CurrentControlSet\Services\mzqnjtaq ), accompanied by the following registry entries: Value Name Value Type Data Type REG_DWORD 1 (Kernel Driver) Start REG_DWORD 1 (System Start) ErrorControl REG_DWORD 0 (Ignore) ImagePath REG_EXPAND_SZ \\??\C:\Windows\system32\drivers\mzqnjtaq.sys Group REG_SZ Boot Bus Extender Args REG_SZ C:\Windows\system32\drivers\mzqnjtaq.sys:changelist At first glance, several characteristics resembled attacker tradecraft: A randomly named driver dropped shortly before reboot Creation of a transient service entry for loading it Presence of RC4 encryption routines Interaction with an Alternate Data Stream ( :changelist ) attached to the driver file Self-cleanup behavior after execution These indicators strongly resembled malicious kernel loader behavior, particularly given prior research into exotic loading mechanisms such as loading kernel drivers directly from ADS paths – a technique often considered theoretical yet has proven practical. The most unusual aspect was that the ADS stream contained an encrypted binary structure used as configuration input for the driver. Encountering a Microsoft-signed driver relying on an ADS-stored encrypted configuration immediately raised suspicion that it might be exploitable or abused by attackers. Our initial hypothesis was that the threat actor had leveraged this driver for post-exploitation activity. That hypothesis ultimately proved incorrect: the behavior was legitimate Defender remediation logic. However, that discovery triggered a deeper analysis of BTR.sys and the surrounding remediation architecture. What began as a false-positive investigation quickly evolved into a full reverse-engineering effort that uncovered undocumented functionality, a custom protocol, and an unexpectedly powerful kernel execution model. Technical Analysis: The BTR Driver Driver Overview Filename: BTR.sys Figure 1: “BTR.sys” driver – Boot Time Removal Tool. Origin: Embedded as a PE resource within MpEngine.dll . It is dropped to disk (with a randomized filename matching [a-z]{8}.sys , e…

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/20/2026, 13:16:03 UTC

Technical Analysis

The Windows Defender Boot-Time Removal driver (BTR.sys) is a signed Microsoft remediation driver embedded within MpEngine.dll and dropped to disk with randomized filenames and service names. It uses an encrypted binary configuration stored in an Alternate Data Stream (:changelist) to perform remediation operations at kernel level. Reverse engineering uncovered the driver’s proprietary transaction format, encrypted configuration mechanism, integrity validation, and execution pipeline. Researchers developed a tool, BTR_CLI, to construct valid encrypted transactions and exercise the driver’s functionality, demonstrating its use as a universal kernel operation engine. This enables attackers to perform arbitrary file and registry operations from Ring 0 without exploiting vulnerabilities or memory corruption, effectively bypassing security solutions by abusing a trusted Microsoft-signed component. The study underscores how defensive technology can be transformed into offensive capability and suggests similar patterns may exist in other signed remediation components.

Potential Impact

The driver’s legitimate remediation functionality can be weaponized to execute arbitrary kernel-level operations, allowing attackers to bypass endpoint security controls such as EDR and antivirus solutions. This abuse leverages a trusted, signed Microsoft driver, which reduces detection likelihood and circumvents typical driver-loading restrictions. Although no vulnerabilities or exploits are required, this capability provides a powerful post-exploitation primitive that can facilitate stealthy persistence and manipulation of system state at the kernel level.

Mitigation Recommendations

No official patch or remediation guidance is currently provided. As this behavior stems from legitimate Windows Defender remediation functionality, mitigation options are limited. Defenders should monitor for unusual usage patterns of the BTR.sys driver, especially randomized driver filenames and service names, and the presence of encrypted Alternate Data Stream configurations. Endpoint security solutions may need to adapt detection strategies to account for abuse of trusted remediation components. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Classification
{"confidence":0.66,"severitySource":"default","classifier":"rss-v2"}
Article Source
{"url":"https://research.checkpoint.com/2026/btr-reforged-weaponizing-defenders-remediation-driver-as-a-kernel-operation-primitive/","fetched":true,"fetchedAt":"2026-08-20T13:15:48.464Z","wordCount":4946}

Threat ID: 6a86fe04acd9273b49a698b4

Added to database: 08/20/2026, 13:15:48 UTC

Last enriched: 08/20/2026, 13:16:03 UTC

Last updated: 08/20/2026, 17:07:34 UTC

Views: 8

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses