
Yazan Sh
@yshCompletionist
0 followers0 downloads8 copies1 like47 views
2 detections
Filters
Last updated
All Time
Detection languages
2
Platforms
2
Detects behavior observed during BTR Reforged execution by correlating a .sys file staged from a user-writable location with subsequent driver service configuration and kernel driver loading within a short time window. The detection focuses on the behavior rather than specific BTR filenames, hashes, or process names.
Detects behavior associated with BTR Reforged by correlating the creation of a Windows kernel driver (.sys), registration of the same driver through a service ImagePath, and the subsequent loading of that driver into the kernel within a short time window. The detection is behavior-based and does not rely on BTR-specific filenames, hashes, process names, or paths. Tested against BTR Reforged in a Microsoft Defender for Endpoint lab environment.
