BigDiskBuster PoC Can Silently Block Microsoft Defender Updates by Exhausting Disk Space

Summary
LevelBlue reproduced and analyzed BigDiskBuster, a proof of concept that repeatedly claims available disk space during Defender updates, causing them to fail while real-time protection remains active.
Key points
- The BigDiskBuster PoC was published on GitHub on September 19, 2026, by the actor known as MSNightmare.
- The tool watches the C:\ volume for Defender update activity and creates hidden temporary files sized to consume available free space, repeatedly reclaiming space as it becomes available.
- In LevelBlue's reproduction, Defender's service and real-time protection remained active, but security intelligence became stale and updates failed with error 0x80070643.
- The analysis found no corresponding endpoint alert; the error code alone does not identify disk exhaustion as the cause.
- Detection signals include a non-Defender process persistently holding both the volume-device and MRT.exe handles, plus hidden GUID-named temporary files and unusual disk-space changes during failed updates.
- The PoC uses standard Windows mechanisms and has no assigned CVE, patch, or Microsoft advisory at the time of publication.
Article Details
- Attack Vectors
- BigDiskBuster watches the C:\ volume for Defender update staging activity, then creates a hidden GUID-named file in %TEMP% with an AllocationSize equal to the available free space, causing the update to fail.
- The tool responds to subsequent FILE_ACTION_MODIFIED notifications by spawning additional allocation threads to reclaim space freed during the update attempt.
- The PoC uses NtCreateFile to hold a raw volume handle and a relative-path handle to MRT.exe, then uses ReadDirectoryChangesW to monitor changes recursively across the volume.
- Defensive Notes
- The researchers observed Defender update failure without a corresponding endpoint alert; the Defender service and real-time protection remained active.
- Investigate persistent MRT.exe handles held by processes outside Defender and TrustedInstaller contexts. Correlating an MRT.exe handle and a volume-device handle in the same non-allowlisted process was the researchers' strongest detection signal.
- Correlate failed Defender update sequences with an abrupt, near-total loss of free space on C:\ and retrieve handle telemetry.
- Check recurring Defender update failures with error 0x80070643 for brief creation of hidden GUID-named files in %TEMP%; the error code alone does not identify disk exhaustion as the cause.
- Monitor whether Defender security intelligence remains current rather than relying solely on service state or reported product health.
MITRE ATT&CK
People
Vendors
Products
DefenderBigDiskBuster, published on GitHub on September 19, 2026, by the actor known as MSNightmare, shows that Defender doesn't need to be disabled to stop receiving updates, it just needs a much simpler dependency: diskMicrosoft WindowsUnlike ShieldCrash, which relied on a Windows path-resolution flaw, BigDiskBuster requires no vulnerability.
Tools
BigDiskBusterA new proof of concept called BigDiskBuster, published on GitHub on September 19, 2026, by the actor known as MSNightmare, shows that Defender doesn't need to be disabled to stop receiving updates, it just needs a muchProcess MonitorProcess Monitor captured a sustained burst of file operations attributed to BigDiskBuster's PID, including repeated IRP_MJ_CREATE operations against multiple GUID-named temporary files.ShieldCrashUnlike ShieldCrash, which relied on a Windows path-resolution flaw, BigDiskBuster requires no vulnerability.