esearch by: Jiřà Vinopal (@vinopaljiri) Abstract What if a trusted security component could be repurposed into an attacker-controlled kernel primitive? What if a signed Microsoft remediation driver could be instructed to execute arbitrary file and registry operations from Ring 0 without exploits, vulnerabilities, or memory corruption? In this publication, we present the first full […]
First seen on research.checkpoint.com
Jump to article: research.checkpoint.com/2026/btr-reforged-weaponizing-defenders-remediation-driver-as-a-kernel-operation-primitive/
![]()

