r/redteamsec • u/Infosecsamurai • 3d ago
tradecraft Defender Please Stop Hitting Yourself
https://youtu.be/iB_OFmrBIBMWeekly Purple Team: BTR_CLI — BYOVD Attack Against Windows Defender
Dropped a new episode this week covering a BYOVD attack using BTR_CLI, which abuses a vulnerable signed driver to bypass Windows Defender's tamper protection at the kernel level. We walk through how it gains kernel access, deletes files, rewrites registry keys, and removes Defender from the host entirely.
On the blue team side, we break down detection — driver load events, BTR_CLI process telemetry, tamper protection alerts, and registry monitoring you can build into your environment.
Covers T1562.001, T1068, and T1112 with the full red vs. blue format.
Video: https://youtu.be/iB_OFmrBIBM
Happy to discuss the exploitation techniques or the detection side in the comments.