AN1193
Analytic 1193
Windows
Processes accessing raw logical drives (e.g., \.\C:) to bypass file system protections or directly manipulate data structures.
WinEventLog:Sysmon
EventCode=10
WinEventLog:Security
EventCode=4688
[TargetObjectPattern]
Regex pattern to detect access to raw disk volumes like `\Device\HarddiskVolume` or `\.\PhysicalDrive*`.
[ParentProcess]
Tune for known tools/scripts (e.g., powershell.exe, cmd.exe) often used in misuse scenarios.
[TimeWindow]
Correlate file access and creation across a short time window to avoid false positives.
AN1194
Analytic 1194
Network Devices
CLI or automated utilities accessing raw device volumes or flash storage directly (e.g., via `copy flash:`, `format`, or `partition` commands).
networkdevice:cli
command logging
[CommandScope]
Limit detection to volume-level commands (e.g., `format`, `copy`, `mount`, `erase`).
[DeviceTypeFilter]
Filter by internal vs. removable volume interactions (e.g., flash, SD card).