Direct Volume Access T1006

Tactic: Stealth

Adversaries may directly access a volume to bypass file access controls and file system monitoring. Windows allows programs to have direct access to logical volumes. Programs with direct access may read and write files directly from the drive by analyzing file system data structures. This technique may bypass Windows file access controls as well as file system monitoring tools.

Events covered

3 catalog events are tagged with this technique by at least one rule.

Authoring guide

These 8 rules share fields, values, and exclusions.

Fields filtered most (14 distinct)

These fields appear most often in rule filters.

FieldRulesHowSample values
event.type6eq 5, in 1start, process_started
host.os.type6eq 6
process_name6eq 6, in 1debugfs, bash, busybox, cmd.exe, csh
process.args5eq 2, starts_with 2, contains 1, in 1/dev/sd, /bin/debugfs, /system/volumes/data, /usr/bin/debugfs, mklink
CommandLine3contains 2, starts_with 1/dev/sd, harddiskvolumeshadowcopy, ntds.dit
EventType3eq 3exec
OriginalFileName2eq 1, in 1cmd.exe, powershell.exe, wbadmin.exe
Device1contains 1floppy
Image1contains 1, ends_with 1, eq 1, is_null 1, starts_with 1\appdata\, \appdata\local\githubdesktop\app-, \appdata\local\keybase\upd.exe
ScriptBlockText1in 1invoke-ninjacopy, stealthclosefile, stealthclosefiledelegate
container.id1wildcard 1*
container.security_context.privileged1eq 1true
event.category1eq 1process
process.entry_leader.entry_meta.type1eq 1container

Top indicator values (75 distinct)

These values appear most often in rule predicates.

FieldKindValueRules (here)Corpus reach
event.typeeq
start
51078
EventTypeeq
exec
3576
process_nameeq
debugfs
33
process.argsstarts_with
/dev/sd
23
CommandLinecontains
harddiskvolumeshadowcopy
13
CommandLinecontains
ntds.dit
13
CommandLinestarts_with
/dev/sd
1
Devicecontains
floppy
1
Imagecontains
\appdata\
16
Imagecontains
\appdata\local\githubdesktop\app-
1
Imagecontains
\appdata\local\keybase\upd.exe
1
Imagecontains
\microsoft\
1
Imageends_with
\executables\ssdupdate.exe
1
Imageends_with
\hostmetadata\nvmehostmetadata.exe
1
Imageends_with
\mpdefendercoreservice.exe
1
Imageends_with
\msmpeng.exe
12
Imageends_with
\resources\app\git\mingw64\bin\git.exe
1
Imageends_with
\thor.exe
1
Imageeq
c:\windows\immersivecontrolpanel\systemsettings.exe
1
Imageeq
registry
1
Imageeq
system
13
Imagestarts_with
c:\$windows.~bt\
1
Imagestarts_with
c:\$winreagent\scratch\
1
Imagestarts_with
c:\program files (x86)\
1
Imagestarts_with
c:\program files\
1
Imagestarts_with
c:\programdata\microsoft\windows defender\platform\
1
Imagestarts_with
c:\users\
12
Imagestarts_with
c:\windows\ccm\
1
Imagestarts_with
c:\windows\explorer.exe
1
Imagestarts_with
c:\windows\servicing\
1

Exclusions (37 distinct)

These values appear most often in top-level exclusions.

FieldKindValueRules excluding
process.argseq
-R
3
Devicecontains
floppy
1
Imagecontains
\appdata\
1
Imagecontains
\appdata\local\githubdesktop\app-
1
Imagecontains
\appdata\local\keybase\upd.exe
1
Imagecontains
\microsoft\
1
Imageends_with
\executables\ssdupdate.exe
1
Imageends_with
\hostmetadata\nvmehostmetadata.exe
1
Imageends_with
\mpdefendercoreservice.exe
1
Imageends_with
\msmpeng.exe
1
Imageends_with
\resources\app\git\mingw64\bin\git.exe
1
Imageends_with
\thor.exe
1
Imageeq
c:\windows\immersivecontrolpanel\systemsettings.exe
1
Imageeq
registry
1
Imageeq
system
1

Rules under this technique

These vendors publish rules tagged with this technique.

Platform (all)
Domain (all)

Sigma 1 rule

Elastic 7 rules