Researchers Show How a Signed Windows Defender Driver Could Be Turned Against Security Tools
Check Point researchers reverse-engineered Microsoft Defender’s BTR.sys driver and found that its undocumented transaction protocol could be reproduced to disable antivirus and EDR products from the Windows kernel using a fully legitimate, signed component.
Itagora tiene in archivio titolo e sommario per la ricerca interna. Il testo completo resta sulla fonte. Il link in uscita non invia referrer.