We're updating the issue view to help you get more done. 

File System Logical Offsets

Description

Windows allows programs to have direct access to logical volumes. Programs with direct access may read and write files directly from the drive by analyzing file system data structures. This technique bypasses Windows file access controls as well as file system monitoring tools. (Citation: Hakobyan 2009)

Utilities, such as NinjaCopy, exist to perform these actions in PowerShell. (Citation: Github PowerSploit Ninjacopy)

id

T1006

tactic

defense-evasion

datasources

API monitoring

maturity

Not Tracked

Assignee

Unassigned
Configure