Partition Event ID 1006: Disk connected (partition data)
- Event ID
- 1006
- Channel
- Microsoft-Windows-Partition/Diagnostic
- Provider
- Microsoft-Windows-Partition
- Log file
- Microsoft-Windows-Partition%4Diagnostic.evtx
- Category
- Devices and drivers
- Default logging
- Logged by default
What event 1006 means
Event 1006 in Microsoft-Windows-Partition/Diagnostic is written when the partition manager processes a disk arrival or change. For removable media it is one of the richest artifacts Windows keeps: Manufacturer, Model, SerialNumber, Capacity, BusType, the parent device instance ID, and the raw bytes of the partition table (Mbr or GPT data) and of the first volume boot records (Vbr0, Vbr1...).
The VBR bytes let you recover the volume serial number and file system of each partition even after the device is gone — the same serial found in LNK files, jump lists and prefetch — linking file access on the host to a specific USB drive. ParentId contains the USB instance ID and serial that match Kernel-PnP 400/410 and System 20001.
Records with no partition data (for example a Capacity of 0) are typically written when the device is removed, which helps bound the connection window.
When it is logged
Microsoft-Windows-Partition/Diagnostic log, enabled by default on Windows 10 and later.
Not present on Windows 7 / 8.1. Records are large because of the embedded sector dumps, so the log rolls over relatively quickly.
Key fields
| Field | What it tells you | ||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| DiskNumber | Disk number assigned by Windows (\\.\PhysicalDriveN). | ||||||||||||||
| Manufacturer | Vendor string reported by the device. | ||||||||||||||
| Model | Model string reported by the device. | ||||||||||||||
| SerialNumber | Serial number reported by the disk; may be empty for some readers. | ||||||||||||||
| ParentId | Instance ID of the parent device, e.g. USB\VID_xxxx&PID_xxxx\<serial> — the link to Kernel-PnP events. | ||||||||||||||
| Capacity | Disk size in bytes. | ||||||||||||||
| BusType | Storage bus type (STORAGE_BUS_TYPE).
| ||||||||||||||
| PartitionStyle | Partition table type.
| ||||||||||||||
| PartitionCount | Number of partitions found. | ||||||||||||||
| Mbr | Hex dump of the MBR sector (for MBR disks). | ||||||||||||||
| Vbr0 | Hex dump of the first volume boot record. Contains the file system type and the volume serial number used in LNK files and jump lists. | ||||||||||||||
| IsSystem | Whether this disk holds the system partition. 0 for removable media. |
Common benign sources
- Users plugging in USB drives, SD cards and external disks.
- Virtual disks (VHD/VHDX) mounted on the host.
What attackers do that produces it
- Data exfiltration to USB storage: a new device with a large capacity connected shortly before files are accessed or copied.
Investigation tips
- List devices by
Manufacturer,Model,SerialNumberandCapacity; separate internal disks (IsSystem, SATA/NVMe) from removable ones. - Parse
Vbr0to obtain the volume serial number and search LNK files and jump lists for it. - Join on
ParentIdwith Kernel-PnP 400/410 and System 20001 to get the full connection history.
MITRE ATT&CK techniques
MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.
Sigma rules for this event
No bundled SigmaHQ rule targets this event ID specifically. Rules on related events may still cover the activity.
Run these rules on your logs
Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.