Direct Volume Access T1006
Tactic: Stealth
Adversaries may directly access a volume to bypass file access controls and file system monitoring. Windows allows programs to have direct access to logical volumes. Programs with direct access may read and write files directly from the drive by analyzing file system data structures. This technique may bypass Windows file access controls as well as file system monitoring tools.
Events covered
3 catalog events are tagged with this technique by at least one rule.
| Provider | Event | Title |
|---|---|---|
| Sysmon | Event ID 1 | Process creation |
| Sysmon | Event ID 9 | RawAccessRead |
| Security-Auditing | Event ID 4688 | A new process has been created. |
Authoring guide
These 8 rules share fields, values, and exclusions.
Fields filtered most (14 distinct)
These fields appear most often in rule filters.
Top indicator values (75 distinct)
These values appear most often in rule predicates.
Exclusions (37 distinct)
These values appear most often in top-level exclusions.
Rules under this technique
These vendors publish rules tagged with this technique.