September 20, 2026

When Windows Defender Becomes the Threat

When Windows Defender Becomes the Threat

Your Antivirus Can Be Used Against Itself

Security researchers at Check Point documented this in August 2026, and it should make IT people uncomfortable. A driver that ships with Windows, one that Microsoft digitally signs and uses as part of Defender’s own cleanup process, can be turned into a tool that wipes out security software before Windows even finishes booting. No outside files needed. No software bug to patch. The driver is already sitting on the machine.

The driver is called BTR.sys. It runs at boot time, operates at the kernel level, and has the permissions to delete files and modify the registry before your endpoint protection ever loads. Researchers found a way to point it at security tools instead of malware. The result is a machine that looks protected but isn’t.

This affects Windows 7 through Windows 11 25H2. That covers almost every Windows machine your business is running. Check Point also said it found no sign the technique has been used in a real attack, which makes this a window to prepare rather than an emergency.

Why This Is Different From a Normal Vulnerability

Most vulnerabilities work because someone found a bug. A developer made a mistake, and an attacker exploits it. Microsoft patches the bug, you deploy the update, problem solved. That process, while imperfect, is manageable.

This situation is different. There’s no bug to patch here. The driver does exactly what it was designed to do. The problem is that an attacker who already has elevated access can redirect that behavior. It’s a technique, not a flaw. Microsoft can’t just ship a fix that makes the driver stop working, because legitimate Defender processes depend on it.

What that means practically is that your patch cycle alone won’t close this gap. Fully updated machines are still affected.

Who Actually Gets Hit by Something Like This

Let’s be honest about the attack chain here. To use this technique, an attacker needs to already have significant access to the machine, likely administrator-level. That’s not nothing. It means this isn’t the kind of thing a phishing email alone triggers on day one.

But think about how breaches actually unfold in small businesses. An employee clicks something, credentials get stolen, an attacker spends days or weeks moving around the network quietly. By the time they’re ready to do real damage, they often do have elevated access. That’s exactly the point where disabling your endpoint protection becomes useful to them.

For a 30-person accounting firm in New Jersey or a law office in Manhattan running Microsoft 365, the realistic threat isn’t a nation-state. It’s ransomware operators who have gotten good at exactly this kind of lateral movement followed by defense evasion.

What You Should Actually Do About This

A few things matter more than others right now.

First, limit who has local administrator rights. This is unglamorous advice, and businesses push back on it constantly because it creates friction. But if a regular user account can’t install software or change system settings, an attacker working with that account can’t easily reach the level of access this technique requires. Intune has policy controls to manage this without making your employees miserable.

Second, make sure your endpoint detection and response tool, whether that’s Defender for Business, CrowdStrike, or something else, is centrally monitored. A security product that gets disabled at 2am on a Tuesday should generate an alert somewhere that a human sees. If your current setup doesn’t do that, it’s a gap worth closing.

Third, watch for new Microsoft guidance on this specific driver. Microsoft is aware of the research. They may issue hardening recommendations, updated Defender policies, or configuration changes through Windows Update for Business. That’s different from a patch, but it still matters. Staying current on those advisories is part of the job.

Finally, think about whether your backup and recovery posture assumes your security tools might be offline during an attack. Good backups stored somewhere an attacker can’t reach them, like immutable cloud storage, give you options when prevention fails. That only holds if someone tests those backups on a schedule.

The Honest Bottom Line

There’s no single fix for this. The right response is layered controls, monitored endpoints, and tight access policies. That’s not exciting, but it’s accurate. If you’re not sure where your environment stands on any of this, Exine works with small and mid-size businesses across NJ and NYC through managed IT and cybersecurity to sort exactly that out.

Tomasz Sobolewski, founder of Exine LLC
About the author
Tomasz Sobolewski
Founder of Exine LLC. Hands-on IT, cybersecurity and backup for growing New Jersey businesses, with 15+ years in the field. The kind of support that knows your systems and picks up the phone.