{"id":"T1006","name":"Direct Volume Access","url":"https://attack.mitre.org/techniques/T1006","tactics":["stealth"],"platforms":["Network Devices","Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0426","stix_id":"x-mitre-detection-strategy--ee674b38-f59a-4f21-860a-19d065e13aaf","name":"Detection of Direct Volume Access for File System Evasion","url":"https://attack.mitre.org/detectionstrategies/DET0426","analytics":[{"id":"AN1193","stix_id":"x-mitre-analytic--126a43e3-7b39-4312-ba15-aab0f7ce78f9","name":"Analytic 1193","description":"Processes accessing raw logical drives (e.g., \\.\\C:) to bypass file system protections or directly manipulate data structures.","url":"https://attack.mitre.org/detectionstrategies/DET0426#AN1193","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Sysmon","channel":"EventCode=10","data_component":"DC0035","data_component_name":"Process Access","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Security","channel":"EventCode=4688","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"wineventlog-security"}],"mutable_elements":[{"field":"TargetObjectPattern","description":"Regex pattern to detect access to raw disk volumes like `\\Device\\HarddiskVolume` or `\\.\\PhysicalDrive*`."},{"field":"ParentProcess","description":"Tune for known tools/scripts (e.g., powershell.exe, cmd.exe) often used in misuse scenarios."},{"field":"TimeWindow","description":"Correlate file access and creation across a short time window to avoid false positives."}],"live":true,"detection_strategies":["DET0426"],"techniques":["T1006"]},{"id":"AN1194","stix_id":"x-mitre-analytic--892f06ae-6a95-438b-8219-49b3384a4d24","name":"Analytic 1194","description":"CLI or automated utilities accessing raw device volumes or flash storage directly (e.g., via `copy flash:`, `format`, or `partition` commands).","url":"https://attack.mitre.org/detectionstrategies/DET0426#AN1194","platforms":["Network Devices"],"log_source_references":[{"name":"networkdevice:cli","channel":"command logging","data_component":"DC0064","data_component_name":"Command Execution","log_source_slug":"networkdevice-cli"}],"mutable_elements":[{"field":"CommandScope","description":"Limit detection to volume-level commands (e.g., `format`, `copy`, `mount`, `erase`)."},{"field":"DeviceTypeFilter","description":"Filter by internal vs. removable volume interactions (e.g., flash, SD card)."}],"live":true,"detection_strategies":["DET0426"],"techniques":["T1006"]}],"live":true,"version":"1.0","techniques":["T1006"]}],"sigma_rules":[{"id":"db809f10-56ce-4420-8c86-d6a7d793c79c","title":"Potential Defense Evasion Via Raw Disk Access By Uncommon Tools","author":"Teymur Kheirkhabarov, oscd.community","status":"test","level":"low","date":"2019-10-22","modified":"2025-12-03","description":"Detects raw disk access using uncommon tools or tools that are located in suspicious locations (heavy filtering is required), which could indicate possible defense evasion attempts","references":["https://www.slideshare.net/heirhabarov/hunting-for-credentials-dumping-in-windows-environment"],"logsource":{"product":"windows","category":"raw_access_thread"},"tags":["attack.stealth","attack.t1006"],"path":"rules/windows/raw_access_thread/raw_access_thread_susp_disk_access_using_uncommon_tools.yml","techniques":["T1006"],"cves":[]}],"kev_cves":[],"_built":"2026-08-23 05:47 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}