BigDiskBuster, a novel proof-of-concept (PoC) cyberattack technique, has been found to prevent Windows Defender from receiving updates without exploiting a vulnerability. Dubbed “BigDiskBuster” by researchers from LevelBlue, this PoC was originally published on September 19 by security researcher Abdelhamid Naceri, who goes by MSNightmare. The technique is capable of leaving Microsoft Defender running while blocking updates, creating a silent virus detection gap.
The BigDiskBuster technique works by watching the C:\ volume for Defender update activity and creating a hidden file that claims essentially all available free space when an update begins. This results in the Defender update failing, as there is no available disk space to complete the process. However, Defender’s service continues to run, and real-time protection remains active. The important aspect of BigDiskBuster is that it does not cause any obvious product failure; instead, it quietly stops keeping the endpoint current.
LevelBlue researchers were able to reproduce the PoC and tested its effectiveness on a live Defender platform update. They found that BigDiskBuster created a “silent detection gap,” in which Defender continues to operate and appears healthy yet is not receiving updates. The technique combines four different mechanisms, including a raw device handle, a relative file open, a recursive volume watch, and an oversized allocation.
The indicators of compromise for BigDiskBuster are relatively easy to spot, particularly at the I/O layer. Researchers have identified high-confidence signals that defenders can use outside of the scope of a Defender detection. These include repeated Defender update failures, especially error code 0x80070643, combined with unusual handle activity or hidden disk-allocation behavior.
While BigDiskBuster is not an EDR killer, it could theoretically extend the useful lifetime of malicious tooling already on a victim’s machine by preventing that endpoint from receiving new Defender detections for it. Microsoft has acknowledged the technique and advises customers to keep their Defender security intelligence and platform updates current.
To mitigate this type of attack, organizations should look beyond whether Defender is running and monitor whether its protection content is staying current. By doing so, defenders can identify unusual activity and take corrective action before it becomes operationally significant. Repeated Defender update failures, combined with unusual handle activity or hidden disk-allocation behavior, can provide the signal needed to detect this type of attack.
As LevelBlue researchers urge, organizations should not rely solely on whether Defender is running but instead monitor its protection content for signs of tampering. By staying vigilant and monitoring their systems closely, defenders can prevent silent detection gaps like BigDiskBuster from going undetected.
Source: Dark Reading — 2026-10-06