Check Point Research has revealed a technique called "BTR Reforged" that weaponizes Microsoft Defender's own legitimately signed boot-time driver, BTR.sys, to perform kernel-level file and registry operations — including deleting entire security software stacks — on all Windows versions from 7 through 11 25H2. Because BTR.sys is a built-in Windows component rather than a third-party driver, it cannot be blocklisted without breaking Defender itself, and a live demonstration at Black Hat USA 2026 showed it successfully removing Defender with Tamper Protection active. Microsoft has declined to issue a patch, stating the technique requires pre-existing administrative privileges and therefore does not meet its criteria for immediate servicing.