Toggle light / dark theme

‘BigDiskBuster’ Leaves Microsoft Defender Running, Blocks Updates

BigDiskBuster contains approximately 300 lines of C++ and combines four different mechanisms including, the post explained, “a raw device handle, a relative file open, a recursive volume watch, and an oversized allocation.”

Lister tells Dark Reading that LevelBlue’s testing environment was “primarily targeted at standard, out-of-the-box Defender installations on Windows assets with the goal of testing if the PoC worked as described and to help identify behaviors related to successful exploitation.” As such, researchers found BigDiskBuster can run successfully under a standard user account.

While not quite an EDR killer, the technique could theoretically extend the useful lifetime of malicious tooling already on a victim’s machine by preventing that endpoint from receiving new Defender detections for it.

Leave a Comment

Lifeboat Foundation respects your privacy! Your email address will not be published.

/* */