BTR Reforged - Suspicious Driver Staging from Writable Locations

Detects behavior observed during BTR Reforged execution by correlating a .sys file staged from a user-writable location with subsequent driver service configuration and kernel driver loading within a short time window. The detection focuses on the behavior rather than specific BTR filenames, hashes, or process names.

Microsoft Sentinel (KQL)