{"id":244974,"date":"2026-10-06T22:02:55","date_gmt":"2026-10-07T03:02:55","guid":{"rendered":"https:\/\/lifeboat.com\/blog\/2026\/10\/bigdiskbuster-leaves-microsoft-defender-running-blocks-updates"},"modified":"2026-10-06T22:02:55","modified_gmt":"2026-10-07T03:02:55","slug":"bigdiskbuster-leaves-microsoft-defender-running-blocks-updates","status":"publish","type":"post","link":"https:\/\/lifeboat.com\/blog\/2026\/10\/bigdiskbuster-leaves-microsoft-defender-running-blocks-updates","title":{"rendered":"\u2018BigDiskBuster\u2019 Leaves Microsoft Defender Running, Blocks Updates"},"content":{"rendered":"<p><a class=\"aligncenter blog-photo\" href=\"https:\/\/lifeboat.com\/blog.images\/bigdiskbuster-leaves-microsoft-defender-running-blocks-updates.jpg\"><\/a><\/p>\n<p>BigDiskBuster contains approximately 300 lines of C++ and combines four different mechanisms including, the post explained, \u201ca raw device handle, a relative file open, a recursive volume watch, and an oversized allocation.\u201d<\/p>\n<p>Lister tells Dark Reading that LevelBlue\u2019s testing environment was \u201cprimarily targeted at standard, out-of-the-box Defender installations on Windows assets with the goal of testing if the PoC worked as described and to help identify behaviors related to successful exploitation.\u201d As such, researchers found BigDiskBuster can run successfully under a standard user account.<\/p>\n<p>While not quite an <a class=\"\" rel=\"noreferrer\" target=\"_blank\" href=\"https:\/\/www.cybersecuritydive.com\/news\/ransomware-gangs-vulnerable-drivers-edr-killers-increasing\/743709\/\" data-airgap-id=\"35\">EDR killer<\/a>, the technique could theoretically extend the useful lifetime of malicious tooling already on a victim\u2019s machine by preventing that endpoint from receiving new Defender detections for it.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>BigDiskBuster contains approximately 300 lines of C++ and combines four different mechanisms including, the post explained, \u201ca raw device handle, a relative file open, a recursive volume watch, and an oversized allocation.\u201d Lister tells Dark Reading that LevelBlue\u2019s testing environment was \u201cprimarily targeted at standard, out-of-the-box Defender installations on Windows assets with the goal of [\u2026]<\/p>\n","protected":false},"author":427,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[20],"tags":[],"class_list":["post-244974","post","type-post","status-publish","format-standard","hentry","category-futurism"],"_links":{"self":[{"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/posts\/244974","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/users\/427"}],"replies":[{"embeddable":true,"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/comments?post=244974"}],"version-history":[{"count":0,"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/posts\/244974\/revisions"}],"wp:attachment":[{"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/media?parent=244974"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/categories?post=244974"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/tags?post=244974"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}