BigDiskBuster PoC Can Silently Block Microsoft Defender Updates by Exhausting Disk Space

· Original article ↗

Summary

LevelBlue reproduced and analyzed BigDiskBuster, a proof of concept that repeatedly claims available disk space during Defender updates, causing them to fail while real-time protection remains active.

Key points

  • The BigDiskBuster PoC was published on GitHub on September 19, 2026, by the actor known as MSNightmare.
  • The tool watches the C:\ volume for Defender update activity and creates hidden temporary files sized to consume available free space, repeatedly reclaiming space as it becomes available.
  • In LevelBlue's reproduction, Defender's service and real-time protection remained active, but security intelligence became stale and updates failed with error 0x80070643.
  • The analysis found no corresponding endpoint alert; the error code alone does not identify disk exhaustion as the cause.
  • Detection signals include a non-Defender process persistently holding both the volume-device and MRT.exe handles, plus hidden GUID-named temporary files and unusual disk-space changes during failed updates.
  • The PoC uses standard Windows mechanisms and has no assigned CVE, patch, or Microsoft advisory at the time of publication.

Article Details

Attack Vectors
  • BigDiskBuster watches the C:\ volume for Defender update staging activity, then creates a hidden GUID-named file in %TEMP% with an AllocationSize equal to the available free space, causing the update to fail.
  • The tool responds to subsequent FILE_ACTION_MODIFIED notifications by spawning additional allocation threads to reclaim space freed during the update attempt.
  • The PoC uses NtCreateFile to hold a raw volume handle and a relative-path handle to MRT.exe, then uses ReadDirectoryChangesW to monitor changes recursively across the volume.
Defensive Notes
  • The researchers observed Defender update failure without a corresponding endpoint alert; the Defender service and real-time protection remained active.
  • Investigate persistent MRT.exe handles held by processes outside Defender and TrustedInstaller contexts. Correlating an MRT.exe handle and a volume-device handle in the same non-allowlisted process was the researchers' strongest detection signal.
  • Correlate failed Defender update sequences with an abrupt, near-total loss of free space on C:\ and retrieve handle telemetry.
  • Check recurring Defender update failures with error 0x80070643 for brief creation of hidden GUID-named files in %TEMP%; the error code alone does not identify disk exhaustion as the cause.
  • Monitor whether Defender security intelligence remains current rather than relying solely on service state or reported product health.

MITRE ATT&CK

People

Vendors

Products

Tools

Related Articles