BigDiskBuster PoC Can Block Microsoft Defender Updates While Protection Remains Active

Summary
LevelBlue reproduced a PoC that repeatedly consumes free disk space during Microsoft Defender updates, preventing updates while Defender continues running. Microsoft says Defender includes detections and preventions; researchers recommend monitoring update failures and,
Key points
- BigDiskBuster watches the Windows C: volume for Defender update activity and creates a hidden file that claims available free space, causing updates to fail.
- The PoC repeats the process after Defender cleans up its staging directory, leaving Defender running and real-time protection active but its detection content out of date.
- LevelBlue researchers reproduced the technique on standard, out-of-the-box Defender installations; it can run under a standard user account.
- The researchers say the technique could extend the usefulness of malicious tools already on a victim’s machine by delaying new Defender detections.
- Microsoft says Defender Antivirus includes detections and preventions for the PoC and recommends keeping security intelligence and platform updates current.
- Researchers recommend monitoring repeated Defender update failures, including error 0x80070643, alongside unusual handle activity or hidden disk-allocation behavior.
Article Details
- Event Type
- Researchers reproduced a proof-of-concept technique, dubbed BigDiskBuster, that blocks Microsoft Defender updates by repeatedly claiming available disk space during update attempts.
- Impact
- The technique can prevent Defender from receiving detection updates while its service and real-time protection remain active, potentially extending the useful lifetime of malicious tooling already on a victim's machine. LevelBlue reported successful testing, including under a standard user account. Microsoft said Defender Antivirus includes detections and preventions against the PoC. The article reports no assigned CVE, patch, or Microsoft advisory.
People
Abdelhamid NaceriSecurity researcher and former Microsoft employee who published the BigDiskBuster proof of concept; he also published UnDefend.MSNightmareAlias used by Abdelhamid Naceri.Nightmare-EclipseAlso identified in the article as an alias of Abdelhamid Naceri.Serhii MelnykLevelBlue research author who helped reproduce and analyze BigDiskBuster.Timmy ListerLevelBlue research author who helped reproduce and analyze BigDiskBuster.
Vendors
LevelBlueDubbed "BigDiskBuster" by researchers from LevelBlue, the PoC was originally published on Sept. 19 by security researcher and former Microsoft employee Abdelhamid Naceri, who goes by MSNightmare (aka Nightmare-Eclipse).Microsoftfrom LevelBlue, the PoC was originally published on Sept. 19 by security researcher and former Microsoft employee Abdelhamid Naceri, who goes by MSNightmare (aka Nightmare-Eclipse). The GitHub page for the PoC
Products
Microsoft DefenderMicrosoft advisory available for defenders, though a Microsoft spokesperson tells Dark Reading that Microsoft Defender Antivirus includes detections and preventions against the PoC. "Customers should keep MicrosoftMicrosoft WindowsA novel proof-of-concept (PoC) cyberattack technique is capable of preventing Windows Defender from receiving updates without exploiting a vulnerability in the process.
Tools
BigDiskBusterDubbed "BigDiskBuster" by researchers from LevelBlue, the PoC was originally published on Sept. 19 by security researcher and former Microsoft employee Abdelhamid Naceri, who goes by MSNightmare (aka Nightmare-Eclipse).UnDefendbeen taken down, but LevelBlue researchers were able to reproduce it. Naceri compared BigDiskBuster to UnDefend, another PoC he published, which similarly prevents Defender from keeping up-to-date detection content.