Skip to content
Sysmon

Sysmon Event ID 9: Raw disk access read

RawAccessReadSysmon event 9 logs a process reading a drive directly through the \\.\ device path, used to copy locked files such as NTDS.dit or SAM without file APIs.
9
Event ID
9
Channel
Microsoft-Windows-Sysmon/Operational
Provider
Microsoft-Windows-Sysmon
Log file
Microsoft-Windows-Sysmon%4Operational.evtx
Category
Files
Default logging
Needs configuration

What event 9 means

Sysmon event 9 fires when a process opens a volume or disk for raw reading with the \\.\ device notation. Raw reads bypass the file system, so they can copy files that are locked by the OS and they avoid file-level auditing such as Security 4663.

Attackers use this to extract NTDS.dit, the SAM and SYSTEM hives or other locked files by parsing NTFS themselves. Legitimate raw readers exist — disk and backup utilities, defragmentation, antivirus and forensic tools — so baseline which processes normally appear.

When it is logged

Audit policy / configuration

Sysmon installed; filter with <RawAccessRead> rules in the configuration.

Key fields

FieldWhat it tells you
ProcessGuidProcess performing the raw read; pivot to its event 1.
ImageExecutable reading the device. System and disk utilities are common; script hosts are not.
DeviceDevice read, e.g. \Device\HarddiskVolume2.
UserAccount of the process (newer Sysmon versions).

Common benign sources

  • Backup, imaging and disk-management software.
  • Antivirus scans, defrag.exe, chkdsk and Windows maintenance tasks.

What attackers do that produces it

  • PowerShell or a custom tool reading the system volume to copy NTDS.dit on a domain controller or the SAM hive on a workstation.
  • Forensic-style NTFS parsers dropped by attackers to grab locked files.

Investigation tips

  • Pivot on ProcessGuid to event 1 for the command line and parent.
  • Look for files written by the same process (event 11), such as copies of NTDS.dit or registry hives.
  • On domain controllers, treat any raw read by a non-backup process as critical.

MITRE ATT&CK techniques

TechniqueTactics
T1006 Direct Volume AccessStealth
T1003.002 OS Credential Dumping: Security Account ManagerCredential Access
T1003.003 OS Credential Dumping: NTDSCredential Access

MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.

Sigma rules for this event

1 SigmaHQ detection rules (release r2026-07-01) target this event.

  • Low · 1

Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.

Run these rules on your logs

Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.

Sources and further reading