Technique.View on attack.mitre.org
Adversaries may directly access a volume to bypass file access controls and file system monitoring. Windows allows programs to have direct access to logical volumes. Programs with direct access may read and write files directly from the drive by analyzing file system data structures. This technique may bypass Windows file access controls as well as file system monitoring tools.
Utilities, such as `NinjaCopy`, exist to perform these actions in PowerShell. Adversaries may also use built-in or third-party utilities (such as `vssadmin`, `wbadmin`, and esentutl) to create shadow copies or backups of data from system volumes.
Rules on DetectionCode tagged with T1006.
| Rule | Level | Log source |
|---|---|---|
| Potential Defense Evasion Via Raw Disk Access By Uncommon Tools | low | windows / raw_access_thread |
| Used by | Procedure example |
|---|---|
| GroupScattered Spider | Scattered Spider has created volume shadow copies of virtual domain controller disks to extract the `NTDS.dit` file. |
| GroupVolt Typhoon | Volt Typhoon has executed the Windows-native `vssadmin` command to create volume shadow copies. |
| Used by | Procedure example |
|---|---|
| Toolesentutl | esentutl can use the Volume Shadow Copy service to copy locked files such as `ntds.dit`. |
| Used by | Procedure example |
|---|---|
| Campaign2025 Poland Wiper Attacks | During the 2025 Poland Wiper Attacks, the adversaries copied volume shadow copies through executing `vssadmin` in order to dump the `NTDS.dit` file. |
| CampaignAPT28 Nearest Neighbor Campaign | During APT28 Nearest Neighbor Campaign, APT28 accessed volume shadow copies through executing |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.