Bypass Record

Indicator Removal × Microsoft Defender

A publicly-reported instance of Indicator Removal bypassing Microsoft Defender, recorded with its original source. Factual record; no assessment of any specific deployment.

Product
Microsoft Defender
Technique
Indicator Removal
MITRE ATT&CK
T1070
Confidence
High
Severity
Medium
Status
poc
Disclosed
2026-09-21
Config / version noted
Not stated

Provenance

Reported as

prevents Microsoft Defender from completing security updates by exhausting disk space

Mechanism

BigDiskBuster abuses Microsoft Defender's update process by creating large files that consume all available disk space, preventing Defender from downloading and applying security definition updates. It likely manipulates Defender's update staging area or uses its own update mechanism to write excessive data, causing update failures and leaving the endpoint with outdated signatures.

Detection & mitigation

Monitor for abnormal disk usage patterns, especially sudden creation of large files in Defender's update directories or system temp folders. Alert on repeated Defender update failures and low disk space conditions. Implement disk quotas and monitor file creation events via Sysmon or EDR telemetry.

Indicator Removal has also been recorded against

This is a record of a publicly-reported event, not an assessment of any specific organization's deployment. Detection and mitigation notes are drawn from the cited source. Where the source is silent, fields are omitted.