Windows System Log: NTFS File System Driver Event 55 Indicates Possible NTFS Exploitation

Alerts on Windows NTFS Event ID 55 indicating a corrupted file record with a matching filename string in the event description.

FreeReviewedSigma · High · v2
Product
windows
Service
system
Author
Florian Roth (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2021-01-11
Updated
2026-07-31

ATT&CK techniques

Impact
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Discovery

  10. Lateral Movement

  11. Collection

  12. C2

  13. Exfiltration

What it detects

This rule flags Windows System events where the NTFS file system driver reports EventID 55 with a message indicating a corrupted file record. Attackers may exploit NTFS parsing or integrity weaknesses to cause unexpected file-system behavior, corruption, or persistence effects. The detection relies on Windows System log telemetry fields such as Provider_Name, EventID, Origin, and the event description text containing specific corruption indicators.

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.