BTR Reforged – Behavioral Detection of Suspicious Kernel Driver Loading

Detects behavior associated with BTR Reforged by correlating the creation of a Windows kernel driver (.sys), registration of the same driver through a service ImagePath, and the subsequent loading of that driver into the kernel within a short time window. The detection is behavior-based and does not rely on BTR-specific filenames, hashes, process names, or paths. Tested against BTR Reforged in a Microsoft Defender for Endpoint lab environment.

Microsoft Sentinel (KQL)