BEGIN:VCALENDAR
VERSION:2.0
PRODID:Data::ICal 0.24
BEGIN:VEVENT
DESCRIPTION:   'Title: BTR Reforged: Weaponizing Defender's Remediation Dri
 ver as a\n   Kernel Operation Primitive\n   Tags: DEF CON Official Talk | 
 Demo ðŸ’» | Tool ðŸ› \n   When: Friday\, Aug 7\, 12:30 - 13:30 PDT\n   Whe
 re: LVCCW Level 1 Hall 3 1007 (Main Track 2) and DCTV-2 - [1]Map\n\n   Des
 cription:\n\n   What if a trusted security component could be repurposed i
 nto an\n   attacker-controlled kernel primitive? What if a signed Microsof
 t\n   remediation driver could be instructed to execute arbitrary file and
 \n   registry operations from Ring 0 â€” without exploits\, vulnerabilitie
 s\,\n   or memory corruption?\n\n   In this talk\, we present the first fu
 ll reverse engineering of the\n   Windows Defender Boot-Time Removal drive
 r (BTR.sys) and its\n   proprietary transaction format. We dissect its enc
 rypted configuration\n   mechanism\, integrity validation logic\, and exec
 ution pipeline\, and\n   demonstrate how this legitimate remediation compo
 nent can be\n   transformed into a universal kernel operation engine. We i
 ntroduce\n   BTR_CLI\, a research tool that constructs valid encrypted tra
 nsactions\n   and exercises the driver's capabilities.\n\n   We demonstrat
 e how BTR_CLI can be used as an EDR/AV bypass technique\,\n   disarming se
 curity solutions using a trusted Windows built-in\,\n   Microsoft-signed d
 river â€” without relying on typical BYOVD\n   techniques.\n\n   Our resea
 rch reveals how trusted security infrastructure can\n   unintentionally ex
 pose powerful primitives and what this means for\n   defenders. This talk 
 blends reverse engineering\, kernel internals\, and\n   detection engineer
 ing into a practical case study of when defensive\n   technology becomes o
 ffensive capability.\n\n   SpeakerBio:  JiÅ™Ã Vinopal\, Threat Researcher 
 at Check Point Research\n\n   JiÅ™Ã Vinopal is a security researcher\, mal
 ware researcher\, and\n   reverse engineer at Check Point Research\, focus
 ed on advanced cyber\n   threats\, kernel internals\, and the hidden mecha
 nics of undocumented\n   system components. His work spans uncovering nove
 l attack primitives\,\n   reconstructing proprietary protocols from binary
  analysis alone\, and\n   deep-diving into both sophisticated malware fami
 lies and trusted\n   platform components. When he's not buried in disassem
 bly\, he actively\n   shares his knowledge and passion for reverse enginee
 ring across his X\n   account\, YouTube channel\, and blog â€” delivering 
 tips\, tricks\, and\n   technical insights to fellow enthusiasts and the b
 roader security\n   community.\n\n   '\n\n   1. #LVCCW_Level1_Hall3\n\n\n
DTEND:20260807T203000Z
DTSTART:20260807T193000Z
LOCATION:DEF CON Talks - LVCCW Level 1 Hall 3 1007 (Main Track 2) and DCTV-
 2
SUMMARY:BTR Reforged: Weaponizing Defender's Remediation Driver as a Kernel
  Operation Primitive
END:VEVENT
END:VCALENDAR
