BTR Reforged - Suspicious Driver Staging from Writable Locations
Detects behavior observed during BTR Reforged execution by correlating a .sys file staged from a user-writable location with subsequent driver service configuration and kernel driver loading within a short time window. The detection focuses on the behavior rather than specific BTR filenames, hashes, or process names.
Microsoft Sentinel (KQL)

