256 Newsroom — Uganda's Digital News Infrastructure
Consumer Technology

Microsoft Defender's Own Driver Can Be Weaponized to Delete Security Software at Boot - The Hacker News

Share
Microsoft Defender's Own Driver Can Be Weaponized to Delete Security Software at Boot - The Hacker News
Image · Internet

What the report says

BTR Reforged uses Defender's signed BTR.sys with an administrator account and SeLoadDriverPrivilege for kernel file and registry operations.

Read the full report at Internet →

Loading debate for this article…

Other publishers covering this story

No additional verified coverage is currently clustered with this report.

Related reporting