Skip to content
Security & Trust

Defender can report healthy while its updates fail, LevelBlue finds

A proof of concept called BigDiskBuster uses free disk space to stop Defender updates. LevelBlue saw no on-screen alert.

W
WebPulse Newsroom
AI-assisted · 4 min read
Share on X LinkedIn
Defender can report healthy while its updates fail, LevelBlue finds
In brief
  • LevelBlue reproduced BigDiskBuster, a proof of concept that stops Microsoft Defender updates by claiming free disk space. It needs no vulnerability and showed no on-screen alert.
  • The service keeps running and reports healthy, so monitoring that checks only service state would miss it.
  • Teams should track whether Defender's protection content is current and investigate repeated update failures with error 0x80070643.

A security tool that is running is not the same as a security tool that is current. Monitoring that checks only service state would show nothing wrong here. A new proof of concept shows how far apart the two can be.

What LevelBlue found

LevelBlue's SpiderLabs researchers, Serhii Melnyk and Timmy Lister, reproduced a tool called BigDiskBuster. A researcher known as MSNightmare published it on GitHub on September 19, 2026. It stops Microsoft Defender from installing updates. It does not turn Defender off. It needs no vulnerability.

The tool waits for Defender to start an update. It then creates a hidden file that claims all the free space on the C:\ drive. The installer has no room to write, so the update fails. Defender clears its working folder, and the space comes back. The tool repeats the step on the next attempt.

The service keeps running and real-time protection stays on. In the lab, the only sign in the Windows Security update screen was an out-of-date detection-content version, plus error 0x80070643. LevelBlue notes that many unrelated failures can produce this generic installation error.

~300 lines of C++
Size of the proof of concept
Source: LevelBlue SpiderLabs (October 2026)

How it works

LevelBlue says the tool combines four standard Windows features. They are a raw handle to the drive, a file opened relative to that handle, a recursive watch on the whole volume, and an oversized file allocation. It uses no memory corruption, no privilege escalation and no kernel component.

The watch is the trigger. Windows can notify a program when files change. The tool asks to hear about changes across the whole drive. It ignores most of them. It acts when Defender's update folders appear.

The tool then measures the free space on C:\ and reserves all of it in one call. It writes no data. The file is hidden and deletes itself when the handle closes. That leaves little for a later scan to find.

The tool also re-arms. Each time the update folder changes, it starts another allocation thread to claim any space that has opened up. LevelBlue says this is why a one-time cleanup of the disk is not enough.

4
Standard Windows mechanisms combined
Source: LevelBlue SpiderLabs (October 2026)

What this does and does not show

This is a proof of concept tested in a lab. LevelBlue says it targeted standard, out-of-the-box Defender installations. The tool ran under a standard user account.

Dark Reading calls it "not quite an EDR-killer." EDR means endpoint detection and response, the agents that monitor each machine. Dark Reading adds that the technique could, in theory, extend the useful life of malicious tools already on a machine. That machine would stop receiving new detections for them.

The GitHub page has since been taken down. LevelBlue reports no CVE, patch or Microsoft advisory. In a statement to Dark Reading, a Microsoft spokesperson said Defender Antivirus already has detections and protections aimed at this technique. The spokesperson urged customers to install the latest Defender security intelligence and platform updates.

The lesson: health checks measure the engine, not its freshness

This shows why "protected" should mean more than "running." A service check tells you the guard is at the post. It does not tell you the guard has the latest briefing. BigDiskBuster leaves the first answer green and the second one out of date.

The person who carries this risk is the analyst reading a clean dashboard. Nothing is flagged, so nothing prompts a question. The only trace the analyst sees on the endpoint is a stale version and an error code that looks like routine noise.

Deeper traces do exist. LevelBlue offers ways to catch them. A process holding both the drive handle and a handle to MRT.exe is, in its words, the highest-confidence signal. The drive handle alone is weak, because legitimate Windows processes can hold it too.

Hidden, GUID-named files that appear and vanish in the temp folder during update failures are another clue. LevelBlue's sample query looks for such a file and MpRecovery.exe running within 30 seconds of each other.

30 seconds
Time window in LevelBlue's sample hunting query
Source: LevelBlue SpiderLabs (October 2026)

Questions for your security team

Ask whether you track the age of Defender's security intelligence on each endpoint, not just whether the service runs. Ask who sees repeated 0x80070643 failures. Ask whether anyone investigates them instead of retrying.

Ask whether your endpoint tools can report handle activity and short-lived hidden files. Ask how fast the team can pull that data. LevelBlue notes the file disappears, though the handles may not.

Confirm that machines have the latest Defender updates, as Microsoft advises. Then ask whether you can spot a sudden, near-total drop in free space on C:\ during a failed Defender update. LevelBlue describes that pairing as a reason to pull handle data. The tool works on whatever free space a drive has, so a roomy disk gives no protection.

A green light tells you the engine is on. It does not tell you the engine is up to date.

Produced by the WebPulse Newsroom with AI assistance from the original reporting credited below, and checked against that source by our editorial review. How we use AI.
Original reporting: LevelBlue.

Share this insight