RESEARCHERS from LevelBlue have reproduced a novel PoC attack named BigDiskBuster that can prevent Windows Defender from receiving updates without exploiting a vulnerability in the updater process. The technique monitors Defender update activity on the C:\ drive and, when an update starts, creates a hidden file that effectively claims most of the available free disk space.
With the disk space depleted, the Defender update fails while the Defender service continues to run and real-time protection remains active, producing a silent detection gap rather than a visible failure.
LevelBlue’s testing found that BigDiskBuster consists of roughly 300 lines of C++ and employs four mechanisms—an raw device handle, a relative file open, a recursive volume watch, and an oversized allocation—to orchestrate the space exhaustion. The PoC can operate under a standard user account and does not require Defender to be in a particular state beyond the update cycle beginning.
While there is no assigned CVE or official Microsoft advisory for BigDiskBuster, Microsoft has stated that Defender includes detections and protections against the technique, and researchers advise defenders to monitor not only Defender’s running status but also whether its protection content remains current. They highlight signals such as repeated Defender update failures (notably 0x80070643), unusual I/O activity, or hidden disk-allocation patterns as practical indicators of compromise.
The article notes that the indicators are observable at the I/O layer and urges organisations to act on those signals to detect potential exploitation before it becomes operationally significant.