Cybersecurity News

Filters
Tag
Reset

Filtered by tag: driver abuse × Clear

BTR Reforged: Weaponizing Defender’s Remediation Driver as a Kernel Operation Primitive

Researchers found Microsoft Defender's signed remediation driver can be repurposed as a kernel-level attack primitive without exploits or memory corruption. By instructing the trusted driver to execute arbitrary file and registry operations from Ring 0, attackers gain powerful kernel access. The technique requires no vulnerabilities, leveraging a legitimate Microsoft component against itself.