Skip to content

Hide Navigation Hide TOC

Suspicious IO.FileStream (70ad982f-67c8-40e0-a955-b920c2fa05cb)

Open a handle on the drive volume via the \.\ DOS device path specifier and perform direct access read of the first few bytes of the volume.

Cluster A Galaxy A Cluster B Galaxy B Level
Suspicious IO.FileStream (70ad982f-67c8-40e0-a955-b920c2fa05cb) Sigma-Rules Clear Command History - T1070.003 (3aef9463-9a7a-43ba-8957-a867e07c1e6a) Attack Pattern 1
Indicator Removal - T1070 (799ace7f-e227-4411-baa0-8868704f2a69) Attack Pattern Clear Command History - T1070.003 (3aef9463-9a7a-43ba-8957-a867e07c1e6a) Attack Pattern 2