[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fsXTSiigk0GO89e-d7nVuQPdnq-WMWt--5y-X5DA_-0U":3},{"article":4,"iocs":41},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":24,"category":25,"article_tags":28},"16e0befa-1130-4b61-8ab9-d3330fabb3d9","'BigDiskBuster' Leaves Microsoft Defender Running While Blocking Updates","bigdiskbuster-leaves-microsoft-defender-running-while-blocking-updates-220ffe","Not quite an EDR-killer, but the proof-of-concept cyber technique creates a silent virus detection gap while service runs normally, no exploit required.","A new proof-of-concept technique called 'BigDiskBuster' has been demonstrated that can create a silent gap in virus detection by preventing Microsoft Defender from updating its definitions. This method doesn't require exploits and allows the antivirus service to appear to be running normally, making it difficult to detect the compromise.","BigDiskBuster technique bypasses Microsoft Defender by blocking updates while remaining undetected.",null,"https:\u002F\u002Fwww.darkreading.com\u002Fapplication-security\u002Fbigdiskbuster-microsoft-defender-running-blocking-updates","https:\u002F\u002Feu-images.contentstack.com\u002Fv3\u002Fassets\u002Fblt6d90778a997de1cd\u002Fblt3886ee964b5d16f1\u002F6ac4000875ac86196ed5f175\u002Fbroken_hard_drive-Bryngelzon-GettyImages-115958814.jpg?width=720&quality=80&disable=upscale","2026-10-06T16:59:24+00:00","2026-10-06T18:00:22.331565+00:00",7,[18,21],{"name":19,"type":20},"Microsoft Defender","product",{"name":22,"type":23},"EDR","technology","89f78b1c-3503-45a1-9fc7-e23d2ce1c6d5",{"id":24,"icon":11,"name":26,"slug":27},"Malware","malware",[29,34,36],{"category":30},{"id":31,"icon":11,"name":32,"slug":33},"02371804-cf6d-4449-98de-f1a2d4d9b266","Tools","tools",{"category":35},{"id":24,"icon":11,"name":26,"slug":27},{"category":37},{"id":38,"icon":11,"name":39,"slug":40},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[]]