If you are not sure if the website you would like to visit is secure, you can verify it here. Enter the website address of the page and see parts of its content and the thumbnail images on this site. None (if any) dangerous scripts on the referenced page will be executed. Additionally, if the selected site contains subpages, you can verify it (review) in batches containing 5 pages.
favicon.ico: attack.mitre.org/techniques/T1006 - Direct Volume Access, Techniqu.

site address: attack.mitre.org/techniques/T1006 redirected to: attack.mitre.org/techniques/T1006

site title: Direct Volume Access, Technique T1006 - Enterprise MITRE ATT&CK®

Our opinion (on Friday 14 August 2026 11:21:37 UTC):

GREEN status (no comments) - no comments
After content analysis of this website we propose the following hashtags:



Meta tags:

Headings (most frequently used words):

direct, volume, access, procedure, examples, mitigations, detection, strategy, references,

Text of the page (most frequently used words):
the (13), #access (12), file (12), att (10), all (10), volume (10), and (8), retrieved (8), enterprise (7), may (7), data (6), techniques (6), system (6), direct (6), shadow (6), 2026 (5), ics (5), mobile (5), none (5), esentutl (5), directly (5), copies (5), mitre (4), detection (4), 2024 (4), for (4), such (4), windows (4), vssadmin (4), ntds (4), dit (4), version (4), use (3), cti (3), mitigations (3), defenses (3), sub (3), december (3), nearest (3), neighbor (3), 2025 (3), from (3), logical (3), utilities (3), volumes (3), copy (3), bypass (3), description (3), backups (3), can (3), create (3), apt28 (3), adversaries (3), 2015 (2), corporation (2), are (2), domains (2), resources (2), reference (2), campaigns (2), software (2), groups (2), components (2), analytics (2), strategies (2), assets (2), tactics (2), matrices (2), core (2), objects (2), february (2), october (2), locked (2), using (2), exe (2), september (2), 2019 (2), tom (2), november (2), january (2), ninjacopy (2), accessing (2), raw (2), flash (2), structures (2), analytic (2), name (2), accounts (2), have (2), these (2), backup (2), some (2), endpoint (2), related (2), command (2), has (2), volt (2), typhoon (2), created (2), scattered (2), spider (2), files (2), during (2), through (2), executing (2), order (2), dump (2), campaign (2), poland (2), wiper (2), attacks (2), t1006 (2), controls (2), monitoring (2), programs (2), with (2), technique (2), tools (2), ckcon (2), person (2), tickets (2), faq (2), registered, trademarks, cookie, preferences, website, changelog, privacy, policy, terms, contact, reset, filters, cisa, prc, state, sponsored, actors, compromise, maintain, persistent, critical, infrastructure, microsoft, 2023, octo, tempest, crosses, boundaries, facilitate, extortion, encryption, destruction, march, cary, 2018, koessel, sean, adair, steven, lancaster, attack, how, russian, apt, weaponized, nearby, networks, covert, cert, polska, energy, sector, incident, report, april, lolbas, bialek, invoke, ps1, june, 2016, hakobyan, 2009, fdump, dumping, sectors, disk, offsets, 2014, references, cli, automated, device, storage, via, commands, partition, format, an1194, processes, drives, protections, manipulate, an1193, evasion, det0426, strategy, ensure, only, required, configure, manage, privileges, monitor, unauthorized, activity, user, account, management, m1018, security, solutions, configured, block, types, behaviors, efforts, adversary, execution, preventing, api, calls, services, behavior, prevention, m1040, mitigation, executed, native, g1017, virtual, domain, controller, disks, extract, g1015, service, s0404, accessed, c0051, copied, c0063, procedure, examples, live, permalink, last, modified, 2017, simpson, crowdstrike, falcon, overwatch, contributors, network, devices, platforms, stealth, tactic, exist, perform, actions, powershell, also, built, third, party, wbadmin, allows, read, write, drive, analyzing, this, well, home, open, join, mclean, hotel, location, details, found, register, here, search, blog, contribute, benefactors, legal, branding, updates, history, engage, advisory, council, learn, more, about, get, started, detections,


Text of the page (random words):
direct volume access technique t1006 enterprise mitre att ck matrices enterprise mobile ics tactics enterprise mobile ics techniques enterprise mobile ics defenses mitigations enterprise mobile ics assets detections detection strategies analytics data components cti groups software campaigns resources get started learn more about att ck att ck advisory council att ckcon att ck data tools faq engage with att ck version history updates legal branding benefactors contribute blog search att ckcon 7 0 in person tickets are open join us october 27 28 2026 in mclean va register here for in person tickets hotel and location details can be found in the faq home techniques enterprise direct volume access direct volume access adversaries may directly access a volume to bypass file access controls and file system monitoring windows allows programs to have direct access to logical volumes programs with direct access may read and write files directly from the drive by analyzing file system data structures this technique may bypass windows file access controls as well as file system monitoring tools 1 utilities such as ninjacopy exist to perform these actions in powershell 2 adversaries may also use built in or third party utilities such as vssadmin wbadmin and esentutl to create shadow copies or backups of data from system volumes 3 id t1006 sub techniques no sub techniques ⓘ tactic stealth ⓘ platforms network devices windows contributors tom simpson crowdstrike falcon overwatch version 3 0 created 31 may 2017 last modified 12 may 2026 version permalink live version procedure examples id name description c0063 2025 poland wiper attacks during the 2025 poland wiper attacks the adversaries copied volume shadow copies through executing vssadmin in order to dump the ntds dit file 4 c0051 apt28 nearest neighbor campaign during apt28 nearest neighbor campaign apt28 accessed volume shadow copies through executing vssadmin in order to dump the ntds dit file 5 s0404 esentutl esentutl can use the volume shadow copy service to copy locked files such as ntds dit 3 6 g1015 scattered spider scattered spider has created volume shadow copies of virtual domain controller disks to extract the ntds dit file 7 g1017 volt typhoon volt typhoon has executed the windows native vssadmin command to create volume shadow copies 8 mitigations id mitigation description m1040 behavior prevention on endpoint some endpoint security solutions can be configured to block some types of behaviors related to efforts by an adversary to create backups such as command execution or preventing api calls to backup related services m1018 user account management ensure only accounts required to configure and manage backups have the privileges to do so monitor these accounts for unauthorized backup activity detection strategy id name analytic id analytic description det0426 detection of direct volume access for file system evasion an1193 processes accessing raw logical drives e g c to bypass file system protections or directly manipulate data structures an1194 cli or automated utilities accessing raw device volumes or flash storage directly e g via copy flash format or partition commands references hakobyan a 2009 january 8 fdump dumping file sectors directly from disk using logical offsets retrieved november 12 2014 bialek j 2015 december 16 invoke ninjacopy ps1 retrieved june 2 2016 lolbas n d esentutl exe retrieved september 3 2019 cert polska 2026 january 30 energy sector incident report 29 december retrieved april 22 2026 koessel sean adair steven lancaster tom 2024 november 22 the nearest neighbor attack how a russian apt weaponized nearby wi fi networks for covert access retrieved february 25 2025 cary m 2018 december 6 locked file access using esentutl exe retrieved september 5 2019 microsoft 2023 october 25 octo tempest crosses boundaries to facilitate extortion encryption and destruction retrieved march 18 2024 cisa et al 2024 february 7 prc state sponsored actors compromise and maintain persistent access to u s critical infrastructure retrieved may 15 2024 core objects all core att ck objects all none matrices tactics techniques sub techniques defenses all defenses all none mitigations assets detection strategies analytics data components cti all cti all none groups software campaigns reference all reference all none resources domains all domains all none enterprise mobile ics reset filters contact us terms of use privacy policy website changelog cookie preferences 2015 2026 the mitre corporation mitre att ck and att ck are registered trademarks of the mitre corporation
Thumbnail images (randomly selected): * Images may be subject to copyright.GREEN status (no comments)
  • External site

Verified site has: 52 subpage(s). Do you want to verify them? Verify pages:

1-5 6-10 11-15 16-20 21-25 26-30 31-35 36-40 41-45 46-50
51-52


The site also has references to the 1 subdomain(s)

  mitre.org  Verify


Top 50 hastags from of all verified websites.

Supplementary Information (add-on for SEO geeks)*- See more on header.verify-www.com

Header

HTTP/1.1 301 Moved Permanently
Connection close
Content-Length 162
Server GitHub.com
Content-Type text/html
Location htt????/attack.mitre.org/techniques/T1006
X-GitHub-Request-Id A86E:CEBAD:15158D:167B53:6A7EFA41
x-github-edge-region uksouth
Accept-Ranges bytes
Age 0
Date Fri, 14 Aug 2026 11:21:37 GMT
Via 1.1 varnish
X-Served-By cache-lcy-egml8630065-LCY
X-Cache MISS
X-Cache-Hits 0
X-Timer S1786706497.476244,VS0,VE79
Vary Accept-Encoding
X-Fastly-Request-ID 07821fa502b05b65497d2ea849470bddaef4a0dc
HTTP/2 301
server GitHub.com
content-type text/html
x-origin-cache HIT
location htt????/attack.mitre.org/techniques/T1006/
access-control-allow-origin *
expires Fri, 14 Aug 2026 11:31:37 GMT
cache-control max-age=600
x-proxy-cache MISS
x-github-request-id 38B6:11DAD2:14C820:162DCD:6A7EFA41
x-github-edge-region uksouth
accept-ranges bytes
age 0
date Fri, 14 Aug 2026 11:21:37 GMT
via 1.1 varnish
x-served-by cache-lcy-egml8630055-LCY
x-cache MISS
x-cache-hits 0
x-timer S1786706498.581129,VS0,VE83
vary Accept-Encoding
x-fastly-request-id 72736f83e9aaf9579b3948ddbbcc5eb3da107bbc
content-length 162
HTTP/2 200
server GitHub.com
content-type text/html; charset=utf-8
x-origin-cache HIT
last-modified Fri, 07 Aug 2026 14:24:18 GMT
access-control-allow-origin *
etag W/ 6a75ea92-bacd
expires Fri, 14 Aug 2026 11:31:37 GMT
cache-control max-age=600
content-encoding gzip
x-proxy-cache MISS
x-github-request-id CA88:136263:14F7AE:165D7E:6A7EFA41
x-github-edge-region uksouth
accept-ranges bytes
age 0
date Fri, 14 Aug 2026 11:21:37 GMT
via 1.1 varnish
x-served-by cache-lcy-egml8630055-LCY
x-cache MISS
x-cache-hits 0
x-timer S1786706498.672042,VS0,VE90
vary Accept-Encoding
x-fastly-request-id 55efb04538a8617a2d4221abed045d6525407e66
content-length 8136

Meta Tags

title="Direct Volume Access, Technique T1006 - Enterprise | MITRE ATT&CK®"
name="google-site-verification" content="2oJKLqNN62z6AOCb0A0IXGtbQuj-lev5YPAHFF_cbHQ"
charset="utf-8"
name="viewport" content="width=device-width, initial-scale=1,shrink-to-fit=no"
http-equiv="X-UA-Compatible" content="IE=edge"

Load Info

page size8136
load time (s)0.768783
redirect count2
speed download10593
server IP 185.199.111.153
* all occurrences of the string "http://" have been changed to "htt???/"