Cybersecurity News
Filters
Filtered by tag: kernel exploitation × Clear
BTR Reforged: Weaponizing Defender’s Remediation Driver as a Kernel Operation Primitive
Researchers found Microsoft Defender's signed remediation driver can be repurposed as a kernel-level attack primitive without exploits or memory corruption. By instructing the trusted driver to execute arbitrary file and registry operations from Ring 0, attackers gain powerful kernel access. The technique requires no vulnerabilities, leveraging a legitimate Microsoft component against itself.
