Threat Intelligence

New 'BigDiskBuster' Technique Can Leave Microsoft Defender Running but Out of Date

Dark Reading · 7 Oct 2026
Key Takeaway Do not rely on Defender simply showing as running: regularly check that security definitions are up to date on every device and investigate any that are falling behind.

Researchers have described a proof-of-concept technique named BigDiskBuster that targets Microsoft Defender in an unusual way. Rather than switching the antivirus off, it blocks updates while the Defender service keeps running as normal.

According to Dark Reading, this is not quite an EDR-killer, which is a tool built to disable endpoint security software outright. Instead, it creates a silent detection gap. The protection still looks active, but it may not recognise newer threats because it cannot receive fresh updates. The report also notes that no exploit is required to achieve this.

The risk for businesses is false confidence. A device showing a running antivirus service may appear healthy, even though its ability to spot new malware is slowly falling behind. The short summary we have does not detail how widely the technique has been seen or how it works, so defenders should watch for further guidance from Microsoft and the researchers.

Microsoft Defender Antivirus Proof of Concept Endpoint Security SMB

Summarised by CISO AI from Dark Reading, written with Claude Sonnet 5.5. We link back to every original so you can read it yourself.