BigDiskBuster Technique Silently Blocks Microsoft Defender Updates
A new cyberattack technique called BigDiskBuster has been discovered, capable of preventing Microsoft Defender from receiving updates without exploiting any vulnerabilities. The proof-of-concept (PoC) was originally published on September 19 by security researcher Abdelhamid Naceri, also known as MSNightmare. Although the GitHub page for the PoC has been taken down, researchers from LevelBlue were able to reproduce it.
The technique works by monitoring the C:\ volume for Defender update activity. When an update begins, it creates a hidden file that claims all available free space, causing the update to fail. Defender then cleans up the staging directory, making the space available again, only for BigDiskBuster to repeat the process on the next update attempt. Notably, Defender's service continues to run, and real-time protection remains active, masking the issue.
LevelBlue's testing confirmed the technique's effectiveness, creating a 'silent detection gap' where Defender appears to operate normally but is not receiving updates. The PoC, written in approximately 300 lines of C++, combines four different mechanisms, including a raw device handle, a relative file open, a recursive volume watch, and an oversized allocation.
While Microsoft Defender Antivirus includes detections and preventions against the PoC, LevelBlue researchers urge organizations to monitor whether Defender's protection content is staying current. Indicators of compromise, such as repeated update failures and unusual handle activity, can help identify this type of attack before it becomes operationally significant.