Detection rules › Sigma
Potential Defense Evasion Via Raw Disk Access By Uncommon Tools
Detects raw disk access using uncommon tools or tools that are located in suspicious locations (heavy filtering is required), which could indicate possible defense evasion attempts
MITRE ATT&CK coverage
| Tactic | Techniques |
|---|---|
| Stealth | T1006 Direct Volume Access |
Event coverage
| Provider | Event | Title |
|---|---|---|
| Sysmon | Event ID 9 | RawAccessRead |
Rule body yaml
title: Potential Defense Evasion Via Raw Disk Access By Uncommon Tools
id: db809f10-56ce-4420-8c86-d6a7d793c79c
status: test
description: Detects raw disk access using uncommon tools or tools that are located in suspicious locations (heavy filtering is required), which could indicate possible defense evasion attempts
references:
- https://www.slideshare.net/heirhabarov/hunting-for-credentials-dumping-in-windows-environment
author: Teymur Kheirkhabarov, oscd.community
date: 2019-10-22
modified: 2025-12-03
tags:
- attack.stealth
- attack.t1006
logsource:
product: windows
category: raw_access_thread
detection:
filter_main_floppy:
Device|contains: floppy
filter_main_generic:
Image|startswith:
- 'C:\$WINDOWS.~BT\'
- 'C:\Program Files (x86)\'
- 'C:\Program Files\'
- 'C:\Windows\CCM\'
- 'C:\Windows\explorer.exe'
- 'C:\Windows\servicing\'
- 'C:\Windows\SoftwareDistribution\'
- 'C:\Windows\System32\'
- 'C:\Windows\SystemApps\'
- 'C:\Windows\SysWOW64\'
- 'C:\Windows\uus\'
- 'C:\Windows\WinSxS\'
filter_main_system_images:
Image:
- 'Registry'
- 'System'
filter_main_windefender:
Image|startswith: 'C:\ProgramData\Microsoft\Windows Defender\Platform\'
Image|endswith:
- '\MsMpEng.exe'
- '\MpDefenderCoreService.exe'
filter_main_microsoft_appdata:
Image|startswith: 'C:\Users\'
Image|contains|all:
- '\AppData\'
- '\Microsoft\'
filter_main_ssd_nvme:
Image|startswith: 'C:\Windows\Temp\'
Image|endswith:
- '\Executables\SSDUpdate.exe'
- '\HostMetadata\NVMEHostmetadata.exe'
filter_main_null:
Image: null
filter_main_systemsettings:
Image: 'C:\Windows\ImmersiveControlPanel\SystemSettings.exe'
filter_main_update:
Image|startswith: 'C:\$WinREAgent\Scratch\'
filter_optional_github_desktop:
Image|startswith: 'C:\Users\'
Image|contains: '\AppData\Local\GitHubDesktop\app-'
Image|endswith: '\resources\app\git\mingw64\bin\git.exe'
filter_optional_nextron:
Image|startswith: 'C:\Windows\Temp\asgard2-agent\'
Image|endswith: '\thor.exe'
filter_optional_Keybase:
Image|startswith: 'C:\Users\'
Image|contains: '\AppData\Local\Keybase\upd.exe'
condition: not 1 of filter_main_* and not 1 of filter_optional_*
falsepositives:
- Likely
level: low
Stages and Predicates
Stage 0: condition
not 1 of filter_main_* and not 1 of filter_optional_*Stage 1: not filter_main_*
filter_main_floppy:
Device|contains: floppy
filter_main_generic:
Image|startswith:
- 'C:\$WINDOWS.~BT\'
- 'C:\Program Files (x86)\'
- 'C:\Program Files\'
- 'C:\Windows\CCM\'
- 'C:\Windows\explorer.exe'
- 'C:\Windows\servicing\'
- 'C:\Windows\SoftwareDistribution\'
- 'C:\Windows\System32\'
- 'C:\Windows\SystemApps\'
- 'C:\Windows\SysWOW64\'
- 'C:\Windows\uus\'
- 'C:\Windows\WinSxS\'
filter_main_system_images:
Image:
- 'Registry'
- 'System'
filter_main_windefender:
Image|startswith: 'C:\ProgramData\Microsoft\Windows Defender\Platform\'
Image|endswith:
- '\MsMpEng.exe'
- '\MpDefenderCoreService.exe'
filter_main_microsoft_appdata:
Image|startswith: 'C:\Users\'
Image|contains|all:
- '\AppData\'
- '\Microsoft\'
filter_main_ssd_nvme:
Image|startswith: 'C:\Windows\Temp\'
Image|endswith:
- '\Executables\SSDUpdate.exe'
- '\HostMetadata\NVMEHostmetadata.exe'
filter_main_null:
Image: null
filter_main_systemsettings:
Image: 'C:\Windows\ImmersiveControlPanel\SystemSettings.exe'
filter_main_update:
Image|startswith: 'C:\$WinREAgent\Scratch\'
Stage 2: not filter_optional_*
filter_optional_github_desktop:
Image|startswith: 'C:\Users\'
Image|contains: '\AppData\Local\GitHubDesktop\app-'
Image|endswith: '\resources\app\git\mingw64\bin\git.exe'
filter_optional_nextron:
Image|startswith: 'C:\Windows\Temp\asgard2-agent\'
Image|endswith: '\thor.exe'
filter_optional_Keybase:
Image|startswith: 'C:\Users\'
Image|contains: '\AppData\Local\Keybase\upd.exe'
Exclusions
Top-level NOT(...) conjuncts: predicates this rule actively suppresses.
| Field | Kind | Excluded values |
|---|---|---|
Image | ends_with | \Executables\SSDUpdate.exe |
Image | ends_with | \HostMetadata\NVMEHostmetadata.exe |
Image | starts_with | C:\Windows\Temp\ |
Image | ends_with | \MpDefenderCoreService.exe |
Image | ends_with | \MsMpEng.exe |
Image | starts_with | C:\ProgramData\Microsoft\Windows Defender\Platform\ |
Image | match | \AppData\ |
Image | match | \Microsoft\ |
Image | starts_with | C:\Users\ |
Device | match | floppy |
Image | eq | C:\Windows\ImmersiveControlPanel\SystemSettings.exe |
Image | eq | Registry |
Image | eq | System |
Image | is_null | |
Image | starts_with | C:\$WINDOWS.~BT\ |
Image | starts_with | C:\$WinREAgent\Scratch\ |
Image | starts_with | C:\Program Files (x86)\ |
Image | starts_with | C:\Program Files\ |
Image | starts_with | C:\Windows\CCM\ |
Image | starts_with | C:\Windows\SoftwareDistribution\ |
Image | starts_with | C:\Windows\SysWOW64\ |
Image | starts_with | C:\Windows\System32\ |
Image | starts_with | C:\Windows\SystemApps\ |
Image | starts_with | C:\Windows\WinSxS\ |
Image | starts_with | C:\Windows\explorer.exe |
Image | starts_with | C:\Windows\servicing\ |
Image | starts_with | C:\Windows\uus\ |
Image | ends_with | \resources\app\git\mingw64\bin\git.exe |
Image | match | \AppData\Local\GitHubDesktop\app- |
Image | starts_with | C:\Users\ |
Image | ends_with | \thor.exe |
Image | starts_with | C:\Windows\Temp\asgard2-agent\ |
Image | match | \AppData\Local\Keybase\upd.exe |
Image | starts_with | C:\Users\ |