Skip to content
Partition

Partition Event ID 1006: Disk connected (partition data)

Partition diagnostic information for a diskPartition event 1006 records a disk's vendor, model, serial, capacity and raw MBR/VBR bytes on connection. Rich USB evidence, incl. volume serials.
1006
Event ID
1006
Channel
Microsoft-Windows-Partition/Diagnostic
Provider
Microsoft-Windows-Partition
Log file
Microsoft-Windows-Partition%4Diagnostic.evtx
Category
Devices and drivers
Default logging
Logged by default

What event 1006 means

Event 1006 in Microsoft-Windows-Partition/Diagnostic is written when the partition manager processes a disk arrival or change. For removable media it is one of the richest artifacts Windows keeps: Manufacturer, Model, SerialNumber, Capacity, BusType, the parent device instance ID, and the raw bytes of the partition table (Mbr or GPT data) and of the first volume boot records (Vbr0, Vbr1...).

The VBR bytes let you recover the volume serial number and file system of each partition even after the device is gone — the same serial found in LNK files, jump lists and prefetch — linking file access on the host to a specific USB drive. ParentId contains the USB instance ID and serial that match Kernel-PnP 400/410 and System 20001.

Records with no partition data (for example a Capacity of 0) are typically written when the device is removed, which helps bound the connection window.

When it is logged

Audit policy / configuration

Microsoft-Windows-Partition/Diagnostic log, enabled by default on Windows 10 and later.

Not present on Windows 7 / 8.1. Records are large because of the embedded sector dumps, so the log rolls over relatively quickly.

Key fields

FieldWhat it tells you
DiskNumberDisk number assigned by Windows (\\.\PhysicalDriveN).
ManufacturerVendor string reported by the device.
ModelModel string reported by the device.
SerialNumberSerial number reported by the disk; may be empty for some readers.
ParentIdInstance ID of the parent device, e.g. USB\VID_xxxx&PID_xxxx\<serial> — the link to Kernel-PnP events.
CapacityDisk size in bytes.
BusTypeStorage bus type (STORAGE_BUS_TYPE).
ValueMeaning
7USB
11SATA
12SD
14Virtual
15File-backed virtual
17NVMe
PartitionStylePartition table type.
ValueMeaning
0MBR
1GPT
2RAW (no partition table)
PartitionCountNumber of partitions found.
MbrHex dump of the MBR sector (for MBR disks).
Vbr0Hex dump of the first volume boot record. Contains the file system type and the volume serial number used in LNK files and jump lists.
IsSystemWhether this disk holds the system partition. 0 for removable media.

Common benign sources

  • Users plugging in USB drives, SD cards and external disks.
  • Virtual disks (VHD/VHDX) mounted on the host.

What attackers do that produces it

  • Data exfiltration to USB storage: a new device with a large capacity connected shortly before files are accessed or copied.

Investigation tips

  • List devices by Manufacturer, Model, SerialNumber and Capacity; separate internal disks (IsSystem, SATA/NVMe) from removable ones.
  • Parse Vbr0 to obtain the volume serial number and search LNK files and jump lists for it.
  • Join on ParentId with Kernel-PnP 400/410 and System 20001 to get the full connection history.

MITRE ATT&CK techniques

TechniqueTactics
T1052.001 Exfiltration Over Physical Medium: Exfiltration over USBExfiltration
T1200 Hardware AdditionsInitial Access
T1091 Replication Through Removable MediaLateral Movement, Initial Access

MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.

Sigma rules for this event

No bundled SigmaHQ rule targets this event ID specifically. Rules on related events may still cover the activity.

Run these rules on your logs

Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.

Sources and further reading