# Researchers show boot-time Defender driver can remove security software

_Wednesday, August 19, 2026 at 8:00 PM EDT · Security · Latest · Tier 2 — Notable_

![Researchers show boot-time Defender driver can remove security software — Primary](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiCbsmb6Wk8pQKWQmByAl5wnZQEVjS7ZYiHrlsHRM7VlcoPL7s30TaoTReoaQ4LI8Oy3KfKlIRHn9sN_7bjEKd_FWPHi1V0JR6LERepKBWSdJOk6cSUNgfIN2KVc6ydfbTILTy11owREYfpO7K11gFQV00l6qf1zl5rzF28jPhcN744yTvRAA-EjyDSBXs/s1700-e365/windows.jpg)

Check Point Research disclosed a technique that uses Microsoft Defender's signed BTR.sys boot-time remediation driver for kernel-level file and registry operations on Windows systems from Windows 7 through Windows 11 25H2. Its proof-of-concept tool can schedule operations at boot, including removal of Defender components before user-mode services start.

The researchers said the technique requires an administrator account with SeLoadDriverPrivilege and found no evidence of real-world abuse. They said Microsoft's security response center did not consider it eligible for immediate servicing because it relies on pre-existing administrative privileges.

## Sources

- [The Hacker News](https://thehackernews.com/2026/08/microsoft-defenders-own-driver-can-be.html)

---
Canonical: https://techandbusiness.org/newswire/_Sof10aqAA4bXSBQ1oTvzC
Retrieved: 2026-08-21T19:07:11.570Z
Publisher: Tech & Business (techandbusiness.org)
