‘BigDiskBuster’ Leaves Microsoft Defender Running While Blocking Updates
Not quite an EDR-killer, but the proof-of-concept cyber technique creates a silent virus detection gap while service runs normally, no exploit required.
Not quite an EDR-killer, but the proof-of-concept cyber technique creates a silent virus detection gap while service runs normally, no exploit required.
A novel proof-of-concept (PoC) cyberattack technique is capable of preventing Windows Defender from receiving updates without exploiting a vulnerability in the process.
Dubbed “BigDiskBuster” by researchers from LevelBlue, the PoC was originally published on Sept. 19 by security researcher and former Microsoft employee Abdelhamid Naceri, who goes by MSNightmare (aka Nightmare-Eclipse). The GitHub page for the PoC has since been taken down, but LevelBlue researchers were able to reproduce it. Naceri compared BigDiskBuster to UnDefend, another PoC he published, which similarly prevents Defender from keeping up-to-date detection content.
BigDiskBuster Blocks Defender Updates
Today’s blog post describes LevelBlue’s efforts to reproduce the PoC, which appears somewhat simple on the surface. As research authors Serhii Melnyk and Timmy Lister explained, BigDiskBuster “watches the C: volume for Defender update activity and, when an update begins, creates a hidden file that claims essentially all available free space.”
With essentially all available disk space claimed, the Defender update fails. Defender then cleans up the staging directory, makes the space available, and BigDiskBuster repeats the process on Defender’s next update attempt. “The important part is what does not happen. Defender’s service keeps running, and real-time protection remains active. There is no obvious product failure — only an update process that quietly stops keeping the endpoint current,” Melnyk and Lister wrote.
LevelBlue’s testing of the technique was successful, and on a live Defender platform update, researchers created what the blog post described as a “silent detection gap,” in which Defender continues to operate and appears healthy yet is not receiving updates.
BigDiskBuster contains approximately 300 lines of C++ and combines four different mechanisms including, the post explained, “a raw device handle, a relative file open, a recursive volume watch, and an oversized allocation.”
Lister tells Dark Reading that LevelBlue’s testing environment was “primarily targeted at standard, out-of-the-box Defender installations on Windows assets with the goal of testing if the PoC worked as described and to help identify behaviors related to successful exploitation.” As such, researchers found BigDiskBuster can run successfully under a standard user account.
Indicators of Compromise Don’t Seem Too Hard to Spot
While not quite an EDR killer, the technique could theoretically extend the useful lifetime of malicious tooling already on a victim’s machine by preventing that endpoint from receiving new Defender detections for it.
LevelBlue’s blog post said BigDiskBuster has no assigned CVE, patch, or Microsoft advisory available for defenders, though a Microsoft spokesperson tells Dark Reading that Microsoft Defender Antivirus includes detections and preventions against the PoC. “Customers should keep Microsoft Defender security intelligence and platform updates current and update to the latest available security intelligence,” the spokesperson adds.
The blog post contains indicators of compromise. Melnyk and Lister explained that activity is easier to distinguish at the I/O layer, and there are high-confidence signals defenders can lean on outside of the scope of a Defender detection. Overall, the researchers urge organizations to look beyond whether Defender is running and to monitor whether its protection content is staying current.
“Repeated Defender update failures, especially 0x80070643, combined with unusual handle activity or hidden disk-allocation behavior,” the researchers wrote, “can provide the signal needed to identify this type of attack before it becomes operationally significant.”