- Sources: Check Point Research, HN 49444878
- Summary: Check Point published research on 2026-08-20, by Jiri Vinopal, on BTR.sys, a Microsoft-signed driver that ships embedded as a PE resource inside MpEngine.dll and is dropped under
System32\drivers with a randomized name when a Defender remediation needs a reboot. The driver exposes no IOCTL interface and instead reads an RC4-encrypted configuration from an alternate data stream named by its service key's Args value, using a hard-coded 256-byte key in .rdata that Check Point reports is consistent across driver versions, with integrity checked by a CRC-32 variant that omits the final inversion. Check Point maps the transaction format and implements six action ids in a tool it calls BTR_CLI, including move with an arbitrary destination and registry set-value, which it describes as arbitrary file write and arbitrary registry write usable for persistence or for disabling security controls. - Why it matters: Loading a kernel driver requires administrative rights, so this is a post-exploitation and EDR-bypass path built on a signed Windows built-in rather than a privilege escalation, and it needs no memory-corruption bug and no vulnerable third-party driver.
- Follow-up: Whether Microsoft changes the driver's configuration handling or the hard-coded key, since there is no CVE and no patch to apply.
send feedback on this story