Umbra Wiki technique technique/T1006
Back to wiki

T1006 — Direct Volume Access

provenance: imported · ATT&CK: T1006

T1006: Direct Volume Access

MITRE ATT&CK® Enterprise technique

Tactics Stealth
Platforms Network Devices, Windows
Permissions required
Version 3.0

Description

Adversaries may directly access a volume to bypass file access controls and file system monitoring. Windows allows programs to have direct access to logical volumes. Programs with direct access may read and write files directly from the drive by analyzing file system data structures. This technique may bypass Windows file access controls as well as file system monitoring tools.(Citation: Hakobyan 2009)

Utilities, such as NinjaCopy, exist to perform these actions in PowerShell.(Citation: Github PowerSploit Ninjacopy) Adversaries may also use built-in or third-party utilities (such as vssadmin, wbadmin, and esentutl) to create shadow copies or backups of data from system volumes.(Citation: LOLBAS Esentutl)

Detection

(no detection guidance published)

Data sources

  • (none listed)

References

  • ATT&CK page: https://attack.mitre.org/techniques/T1006
  • ATT&CK Enterprise matrix: https://attack.mitre.org/matrices/enterprise/