CTIPilot
AI-generated · no human review · verify critical claims against the linked source. how it works →
← Back to the live brief
NOTABLENATOB2research

BigDiskBuster: a roughly 300-line Windows proof of concept keeps Microsoft Defender from updating by claiming all free disk space, with no CVE and no patch

A Defender bypass that needs no vulnerability: fill the disk during every update and the engine stays up, stale

Analysis

LevelBlue SpiderLabs reproduced BigDiskBuster, a proof of concept published on GitHub on 2026-09-19 by the actor known as MSNightmare (Nightmare Eclipse) that needs no vulnerability to keep Microsoft Defender from updating (LevelBlue SpiderLabs, 2026-10-05). It watches the C: volume for Defender update activity and, when an update begins, creates a hidden file whose allocation claims essentially all free space; the update runs out of room and fails, Defender cleans up its staging directory and the tool repeats the process on the next attempt (LevelBlue SpiderLabs, 2026-10-05). The Defender service keeps running and real-time protection stays on; in LevelBlue's lab no alert appeared, and the only visible artifact was a stale security-intelligence version and the generic update error 0x80070643 (LevelBlue SpiderLabs, 2026-10-05). The roughly 300 lines of C++ use no memory corruption or kernel component: a raw handle on the volume device, a file opened relative to that handle, a recursive watch of the volume and an oversized allocation, with the file hidden and deleted on close (LevelBlue SpiderLabs, 2026-10-05). It ran under a standard user account on a default Defender installation (Dark Reading, 2026-10-06).

No CVE, patch or Microsoft advisory exists; a Microsoft spokesperson told Dark Reading that Defender Antivirus includes detections and preventions against the proof of concept and that customers should keep security intelligence and platform updates current (Dark Reading, 2026-10-06). The GitHub repository has been taken down, and Dark Reading notes that the technique could in theory extend the life of malicious tooling already on a machine by withholding new detections (Dark Reading, 2026-10-06). No source reports use in an attack.

Triage: a handle on the volume device alone is low-specificity because svchost, SearchIndexer, dllhost and TiWorker hold the same kind of handle in normal operation; in LevelBlue's tested environment only the Defender service processes and TrustedInstaller legitimately held a handle on MRT.exe (LevelBlue SpiderLabs, 2026-10-05).

Cited evidence

At the time of publication, BigDiskBuster has no assigned CVE, available patch, or Microsoft advisory.

LevelBlue SpiderLabs 2026-10-05

a Microsoft spokesperson tells Dark Reading that Microsoft Defender Antivirus includes detections and preventions against the PoC

Dark Reading 2026-10-06

a process holding both of these handles simultaneously has no ordinary reason to exist on a stock Windows endpoint

LevelBlue SpiderLabs 2026-10-05

Sources2

PROVENANCE

AI-generated · no human review · this permalink is the shareable record for the finding · verify operationally critical claims against the linked primary source.