Direct Volume Access

T1006

Technique.View on attack.mitre.org

About this technique

Adversaries may directly access a volume to bypass file access controls and file system monitoring. Windows allows programs to have direct access to logical volumes. Programs with direct access may read and write files directly from the drive by analyzing file system data structures. This technique may bypass Windows file access controls as well as file system monitoring tools.

Utilities, such as `NinjaCopy`, exist to perform these actions in PowerShell. Adversaries may also use built-in or third-party utilities (such as `vssadmin`, `wbadmin`, and esentutl) to create shadow copies or backups of data from system volumes.

Detection rules1

Rules on DetectionCode tagged with T1006.

Sigma1

RuleLevelLog source
Potential Defense Evasion Via Raw Disk Access By Uncommon Toolslowwindows / raw_access_thread

Splunk0

No Splunk rules are mapped to this technique yet.

Groups2

Software1

Campaigns2

Procedure examples5

Groups2

Used byProcedure example
GroupScattered Spider

Scattered Spider has created volume shadow copies of virtual domain controller disks to extract the `NTDS.dit` file.

GroupVolt Typhoon

Volt Typhoon has executed the Windows-native `vssadmin` command to create volume shadow copies.

Software1

Used byProcedure example
Toolesentutl

esentutl can use the Volume Shadow Copy service to copy locked files such as `ntds.dit`.

Campaigns2

Used byProcedure example
Campaign2025 Poland Wiper Attacks

During the 2025 Poland Wiper Attacks, the adversaries copied volume shadow copies through executing `vssadmin` in order to dump the `NTDS.dit` file.

CampaignAPT28 Nearest Neighbor Campaign

During APT28 Nearest Neighbor Campaign, APT28 accessed volume shadow copies through executing vssadmin in order to dump the NTDS.dit file.

References3

  1. Github PowerSploit Ninjacopy Open source
    Bialek, J. (2015, December 16). Invoke-NinjaCopy.ps1. Retrieved June 2, 2016.
  2. Hakobyan 2009 Open source
    Hakobyan, A. (2009, January 8). FDump - Dumping File Sectors Directly from Disk using Logical Offsets. Retrieved November 12, 2014.
  3. LOLBAS Esentutl Open source
    LOLBAS. (n.d.). Esentutl.exe. Retrieved September 3, 2019.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.