‘BigDiskBuster’ Leaves Microsoft Defender Running While Blocking Updates

A Novel Proof-of-Concept Exploits Microsoft Defender’s Update Mechanism

A sophisticated proof-of-concept (PoC) cyberattack technique has been discovered to silently prevent Windows Defender from receiving updates without exploiting a vulnerability. Dubbed “BigDiskBuster” by researchers, this novel attack allows malicious actors to extend the lifetime of existing malware on compromised machines by blocking Defender updates.

Developed by security researcher Abdelhamid Naceri, who goes by MSNightmare (aka Nightmare-Eclipse), BigDiskBuster creates a hidden file that claims all available free space on the C:\ volume when an update attempt is made. This results in the Defender update failing, yet the service remains operational and real-time protection continues to function. In other words, the attack creates a “silent detection gap” where Defender appears healthy but is not receiving updates.

Researchers from LevelBlue successfully reproduced BigDiskBuster using approximately 300 lines of C++ code that combines four different mechanisms: a raw device handle, a relative file open, a recursive volume watch, and an oversized allocation. According to the researchers, this technique can run successfully under a standard user account and even on standard, out-of-the-box Defender installations.

While not a full-fledged EDR (Endpoint Detection and Response) killer, BigDiskBuster has significant implications for organizations relying on Microsoft Defender for endpoint security. By preventing updates, malicious actors can extend the lifespan of existing malware, rendering traditional detection methods less effective. However, researchers note that indicators of compromise are relatively easy to spot, particularly at the I/O layer.

Microsoft has acknowledged the existence of BigDiskBuster and has stated that its customers should keep Defender’s security intelligence and platform updates current. LevelBlue researchers urge organizations to look beyond whether Defender is running and instead monitor its protection content for signs of tampering or compromise. Specifically, repeated update failures (0x80070643), unusual handle activity, or hidden disk-allocation behavior can signal a potential attack.

As a practical takeaway, it’s essential for security teams to remain vigilant and monitor their systems closely. By staying current with Defender updates and being aware of the signs outlined by LevelBlue researchers, organizations can identify and mitigate this type of attack before it becomes operationally significant.


Source: Dark Reading — 2026-10-06