Full Report
A new proof of concept called BigDiskBuster, published on GitHub on September 19, 2026, by the actor known as MSNightmare, shows that Defender doesn't need to be disabled to stop receiving updates, it just needs a much simpler dependency: disk space.
Analysis Summary
# Tool/Technique: BigDiskBuster
## Overview
BigDiskBuster is a proof-of-concept (PoC) tool designed to silently prevent Microsoft Defender from receiving security intelligence and platform updates. Rather than disabling the antivirus service—which often triggers alerts—it employs a resource exhaustion technique. By monitoring the file system for update activity and immediately consuming all available disk space, it forces the update process to fail while leaving the Defender service in a "healthy" but increasingly stale state.
## Technical Details
- **Type:** Attack Tool / PoC
- **Platform:** Windows (specifically targeting Microsoft Defender)
- **Capabilities:** Filesystem monitoring, dynamic disk space exhaustion, stealthy update blocking.
- **First Seen:** September 19, 2026
## MITRE ATT&CK Mapping
- **[TA0005 - Defense Evasion]**
- **[T1562.001 - Impair Defenses: Disable or Modify Tools]**
- **[TA0040 - Impact]**
- **[T1496 - Resource Hijacking]** (Modified use case: Disk exhaustion to impair security)
## Functionality
### Core Capabilities
- **Update Monitoring:** Uses a filesystem watcher to detect the creation of the Microsoft Defender update staging directory on the `C:\` volume.
- **Disk Exhaustion:** Upon detection of an update, it creates a hidden, GUID-named file in the `%TEMP%` directory. It sets the `AllocationSize` of this file to match the volume's total remaining free space.
- **Race Condition Exploitation:** By "filling the well" (disk space) faster than the update can write its files, it forces an `ERROR_DISK_FULL` condition within the update installer.
### Advanced Features
- **Re-arm Loop:** The tool spawns additional allocation threads in response to `FILE_ACTION_MODIFIED` notifications. If the update process manages to free any space or if the tool's handle is released, it immediately re-allocates the available space until the update cycle fails.
- **Silent Failure:** The tool causes Defender to report a generic error code `0x80070643`. This code is common for many benign update issues, making the attack indistinguishable from routine transient failures in standard monitoring logs.
- **Auto-Cleanup:** The tool releases the disk allocation the moment the update staging directory is removed, ensuring the user does not notice a permanent loss of disk space.
## Indicators of Compromise
- **File Hashes:** No specific hashes provided (source code-based PoC).
- **File Names:** `BigDiskBuster.exe` (though it can be renamed to mimic legitimate system processes).
- **Registry Keys:** N/A.
- **Network Indicators:** None (the tool operates locally).
- **Behavioral Indicators:**
- Repeated `IRP_MJ_CREATE`, `IRP_MJ_QUERY_EA`, and `IRP_MJ_QUERY_INFORMATION` operations against GUID-named files in `\AppData\Local\Temp\`.
- Sudden, short-lived drops in available disk space to near-zero bytes coinciding with Defender update attempts.
- Process behavior: An unidentified user-space executable maintaining a filesystem watcher on Defender staging paths.
## Associated Threat Actors
- **MSNightmare** (Author/Publisher)
## Detection Methods
- **Signature-based detection:** Monitor for the specific GUID-naming convention used for temporary files in `%TEMP%` if the PoC code remains unmodified.
- **Behavioral detection:**
- Alert on repeated Defender update failures with error code `0x80070643`.
- Monitor for processes requesting massive file allocations (Resource Exhaustion) that are released as soon as `MpSigStub.exe` or `UpdatePlatform.amd64fre` terminates.
- Track I/O handles: Look for sustained bursts of file operations against temporary directories during Windows Update windows.
## Mitigation Strategies
- **Prevention measures:** Implement EDR policies that flag or block non-system processes from creating files with massive `AllocationSize` attributes in temporary directories.
- **Hardening recommendations:**
- Monitor the age of Defender Security Intelligence signatures. Alert if signatures are older than a specific threshold (e.g., 48 hours).
- Use "Is Current" status checks rather than just "Is Running" checks for antivirus health monitoring.
## Related Tools/Techniques
- **ShieldCrash:** A previous Defender bypass by MSNightmare that relied on Windows path-resolution flaws.
- **Generic Disk Exhaustion:** Traditional DoS techniques, repurposed here for targeted security impairment.