Sysmon Event ID 9: Raw disk access read
- Event ID
- 9
- Channel
- Microsoft-Windows-Sysmon/Operational
- Provider
- Microsoft-Windows-Sysmon
- Log file
- Microsoft-Windows-Sysmon%4Operational.evtx
- Category
- Files
- Default logging
- Needs configuration
What event 9 means
Sysmon event 9 fires when a process opens a volume or disk for raw reading with the \\.\ device notation. Raw reads bypass the file system, so they can copy files that are locked by the OS and they avoid file-level auditing such as Security 4663.
Attackers use this to extract NTDS.dit, the SAM and SYSTEM hives or other locked files by parsing NTFS themselves. Legitimate raw readers exist — disk and backup utilities, defragmentation, antivirus and forensic tools — so baseline which processes normally appear.
When it is logged
Sysmon installed; filter with <RawAccessRead> rules in the configuration.
Key fields
| Field | What it tells you |
|---|---|
| ProcessGuid | Process performing the raw read; pivot to its event 1. |
| Image | Executable reading the device. System and disk utilities are common; script hosts are not. |
| Device | Device read, e.g. \Device\HarddiskVolume2. |
| User | Account of the process (newer Sysmon versions). |
Common benign sources
- Backup, imaging and disk-management software.
- Antivirus scans,
defrag.exe,chkdskand Windows maintenance tasks.
What attackers do that produces it
- PowerShell or a custom tool reading the system volume to copy
NTDS.diton a domain controller or theSAMhive on a workstation. - Forensic-style NTFS parsers dropped by attackers to grab locked files.
Investigation tips
- Pivot on ProcessGuid to event 1 for the command line and parent.
- Look for files written by the same process (event 11), such as copies of NTDS.dit or registry hives.
- On domain controllers, treat any raw read by a non-backup process as critical.
MITRE ATT&CK techniques
MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.
Sigma rules for this event
1 SigmaHQ detection rules (release r2026-07-01) target this event.
- Low · 1
- LowPotential Defense Evasion Via Raw Disk Access By Uncommon ToolsRule by Teymur Kheirkhabarov, oscd.community, SigmaHQ, DRL 1.1
Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.
Run these rules on your logs
Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.