Security researcher Abdelhamid Naceri has released another proof-of-concept exploit targeting Microsoft Defender that can prevent the antivirus from installing important platform and security intelligence updates.
Called BigDiskBuster, the new tool is described as a successor to Naceri’s earlier UnDefend project, which demonstrated another way to interfere with Defender updates. Naceri says BigDiskBuster works on supported Windows versions, although he acknowledged that the current proof of concept is buggy and still needs work.
The technique does not simply turn Microsoft Defender off. Instead, it interferes with the update process, potentially leaving the antivirus running while preventing it from receiving newer detection updates. Security researchers say this could leave a compromised system relying on outdated protection.
BigDiskBuster is the latest in a series of Windows security exploits released by Naceri during an ongoing dispute with Microsoft. Earlier releases included UnDefend, ShieldCrash, ShieldBreak, RoguePlanet, LegacyHive, BlueHammer, RedSun, YellowKey, GreenPlasma and MiniPlasma, targeting Microsoft Defender, BitLocker and other Windows components.
Microsoft has patched several of the vulnerabilities disclosed by Naceri, including ShieldBreak, RoguePlanet, YellowKey, GreenPlasma and MiniPlasma. However, some of the issues disclosed by the researcher remain without an official fix.
The release comes as Microsoft continues to update Defender across supported Windows systems. Microsoft documents regular Defender platform, engine and security intelligence updates as part of its ongoing protection against newly discovered threats.
If this article helped you, please consider supporting our work. Every small contribution keeps Abijita.com independent and running.
BigDiskBuster is currently a proof of concept rather than a confirmed widespread attack. Its author has also warned that the implementation is still experimental, and its claimed compatibility has not been independently verified.



