Bypass Record
Indicator Removal × Microsoft Defender
A publicly-reported instance of Indicator Removal bypassing Microsoft Defender, recorded with its original source. Factual record; no assessment of any specific deployment.
Mechanism
BigDiskBuster abuses Microsoft Defender's update process by creating large files that consume all available disk space, preventing Defender from downloading and applying security definition updates. It likely manipulates Defender's update staging area or uses its own update mechanism to write excessive data, causing update failures and leaving the endpoint with outdated signatures.
Detection & mitigation
Monitor for abnormal disk usage patterns, especially sudden creation of large files in Defender's update directories or system temp folders. Alert on repeated Defender update failures and low disk space conditions. Implement disk quotas and monitor file creation events via Sysmon or EDR telemetry.
This is a record of a publicly-reported event, not an assessment of any specific organization's deployment. Detection and mitigation notes are drawn from the cited source. Where the source is silent, fields are omitted.