A new tool does not switch Defender off. It just stops it learning.
Windows Security can show a green tick and still be weeks behind. That is the entire point of a tool published on 21 September.
Abdelhamid Naceri, who posts as Nightmare Eclipse, put a proof-of-concept called BigDiskBuster on GitHub. It breaks into nothing and steals nothing. All it does is stop Microsoft Defender from updating. It watches the C: drive for Defender's platform and definition update folders, fills the remaining free space with hidden files so a download has nowhere to land, and locks MRT.exe, the Malicious Software Removal Tool, behind permissions that block writes. Leave it running in the background and Defender stops receiving new detections, on every supported version of Windows. There is no CVE and there is no patch.
The damage is quiet, which is what makes it interesting. Defender still reports itself as on. Real-time protection is still ticked. What goes missing is the roughly daily security intelligence update that teaches it about the malware that appeared since yesterday, plus the platform updates that keep the engine current. An antivirus with stale definitions has stopped being an antivirus and started being a logo. Naceri calls this one a successor to UnDefend, which he released in April and which did much the same job by other means.
He admits the code is still rough, and nobody has reported it in a real attack. Checking takes two minutes anyway. Open Windows Security, go to Virus and threat protection, and read the date under Protection updates; if it is not from the last day or so, click Check for updates. While you are there, see how much free space is left on C:, because a drive with nothing left on it causes this same problem entirely by accident. Tendvane's health score includes a look at your PC's security posture, which is a fast way to notice protection that has quietly gone stale.