'BigDiskBuster' Leaves Microsoft Defender Running While Blocking Updates
Summary
A proof-of-concept technique named 'BigDiskBuster' has been developed that can disable Microsoft Defender's real-time protection and block its updates without triggering alerts or requiring an exploit. The technique allows for a silent gap in virus detection while the service appears to be running normally.
IFF Assessment
FOE
This technique creates a silent gap in security defenses, making it harder for defenders to detect and respond to threats.
Defender Context
Defenders need to be aware of techniques that can bypass or disable endpoint detection and response (EDR) solutions like Microsoft Defender, especially those that operate silently. This highlights the importance of layered security and robust monitoring for unexpected service behavior, not just for active threats.