You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
The RawAccessRead event detects when a process conducts reading operations from the drive using the \.\ denotation. This technique is often used by malware for data exfiltration of files that are locked for reading, as well as to avoid file access auditing tools. The event indicates the source process and target device.
Additional Details
Detail
Value
Type
Templated Match
Category
Impact
Apply Risk to Entities
device_hostname, user_username
Signal Name
Sysmon - RawAccessRead Event
Summary Expression
RawAccessRead Event on {{device_hostname}} with user: {{user_username}}