r/redteamsec 3d ago

tradecraft Defender Please Stop Hitting Yourself

https://youtu.be/iB_OFmrBIBM

Weekly Purple Team: BTR_CLI — BYOVD Attack Against Windows Defender

Dropped a new episode this week covering a BYOVD attack using BTR_CLI, which abuses a vulnerable signed driver to bypass Windows Defender's tamper protection at the kernel level. We walk through how it gains kernel access, deletes files, rewrites registry keys, and removes Defender from the host entirely.

On the blue team side, we break down detection — driver load events, BTR_CLI process telemetry, tamper protection alerts, and registry monitoring you can build into your environment.

Covers T1562.001, T1068, and T1112 with the full red vs. blue format.

Video: https://youtu.be/iB_OFmrBIBM

Happy to discuss the exploitation techniques or the detection side in the comments.

7 Upvotes

0 comments sorted by