Windows Raw Disk Access by Uncommon Process Paths

Alerts on Windows raw disk access by processes from uncommon or suspicious locations.

FreeReviewedSigma · Low · v1
Product
windows
Category
raw_access_thread
Author
Teymur Kheirkhabarov, oscd.community (SigmaHQ), DRL 1.1
Published
2019-10-22
Updated
2026-07-30

ATT&CK techniques

Defense Evasion
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Cred Access

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule flags threads on Windows that access raw disk devices while the accessing process is not identified as a common system binary or well-known software path. Attackers may use raw disk access to bypass higher-level protections and perform stealthy reads or writes during defense evasion. The detection relies on raw access thread telemetry that includes the target device string and the process image path, applying multiple allowlist filters to reduce false positives.

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.