{"id":6679,"date":"2025-09-05T10:04:08","date_gmt":"2025-09-05T10:04:08","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/09\/05\/hackers-leverage-raw-disk-reads-to-bypass-edr-solutions-and-access-highly-sensitive-files\/"},"modified":"2025-09-05T10:04:08","modified_gmt":"2025-09-05T10:04:08","slug":"hackers-leverage-raw-disk-reads-to-bypass-edr-solutions-and-access-highly-sensitive-files","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/09\/05\/hackers-leverage-raw-disk-reads-to-bypass-edr-solutions-and-access-highly-sensitive-files\/","title":{"rendered":"Hackers Leverage Raw Disk Reads to Bypass EDR Solutions and Access Highly Sensitive Files"},"content":{"rendered":"<p>    Hackers Leverage Raw Disk Reads to Bypass EDR Solutions and Access Highly Sensitive Files<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>A new technique that allows attackers to read highly sensitive files on Windows systems, bypassing many of the modern security tools designed to prevent such breaches.<\/p>\n<p>A report from Workday\u2019s Offensive Security team explains how, by reading data directly from a computer\u2019s raw disk, a malicious actor can sidestep <a href=\"https:\/\/cybersecuritynews.com\/best-edr-tools\/\">Endpoint Detection and Response (EDR)<\/a> solutions, file permissions, and other critical protections to steal credential files.<\/p>\n<p>The method avoids standard file-access procedures that are typically monitored by security software. Instead of opening a file by name, the attack involves communicating directly with low-level disk drivers. <\/p>\n<p>An attacker with administrator rights can use built-in Windows drivers, or a user with fewer privileges could exploit a vulnerable third-party driver, to request raw data from a specific location on the physical disk.<\/p>\n<p>This approach is particularly stealthy because the attack never requests a sensitive file like the SAM hive by name. Instead, it asks for the data at a particular sector address. <\/p>\n<figure class=\"wp-block-image size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgHa86K_EqGAh7qcmtg-BtlgjIhKfty80CgEzccAraOIs7qycLqyeJpdTCCzm1cJe24dSoWur_UbeM1aX_YTLdbXBnXle3z2HHhVVwu18hJDb0a6z8GgRx72CpcPypWoApsOFJuiRJUcPFsj9jYeBgRKr1D83k-m8mrQKD3c6N0axy2sugs_Bkj2bQ9NGeI\/s16000\/0_Y561jkASKVou0NKe.webp?ssl=1\" alt=\"raw disk read request\"><figcaption class=\"wp-element-caption\"><em>raw disk read request<\/em><\/figcaption><\/figure>\n<p>This means many security systems, which look for malicious file access by name, are blind to the activity. The <a href=\"https:\/\/cybersecuritynews.com\/edr-vs-mdr\/\" target=\"_blank\" rel=\"noreferrer noopener\">EDR solution<\/a> might see a request to \u201cread sector 12345\u201d instead of an alert-worthy attempt to \u201copen the system\u2019s password file.<\/p>\n<p>\u201d This allows the technique to evade file access controls, exclusive file locks, and even advanced defenses like Virtualization-Based Security (VBS). Furthermore, it leaves no trace in the default system logs.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-how-the-attack-works\"><strong>How the Attack Works<\/strong><\/h2>\n<p>After an attacker obtains the raw disk data, they must parse it to reconstruct the target file. <\/p>\n<p>This process involves interpreting the NTFS file system structure, starting from the Master Boot Record to find the disk partition, then locating the Master File Table (MFT), which serves as a directory for the entire volume. <\/p>\n<p>By reading the MFT, the attacker can pinpoint the exact physical location of any file\u2019s data, read it in clusters, and reassemble it\u2014all without ever officially \u201copening\u201d the file through the operating system.<\/p>\n<p>The Workday team <a href=\"https:\/\/medium.com\/workday-engineering\/leveraging-raw-disk-reads-to-bypass-edr-f145838b0e6d\" target=\"_blank\" rel=\"noreferrer noopener\">demonstrated<\/a> this attack by leveraging a vulnerability (assigned CVE-2025\u201350892) in a driver that improperly exposed this raw read capability.<\/p>\n<p>However, they emphasize that any user with administrative privileges can perform this attack without needing a vulnerable driver, making it a relevant threat in many corporate environments.<\/p>\n<p>Protecting against such a low-level attack is challenging, as it bypasses security layers that many organizations depend on. The researchers recommend a \u201cdefense in depth\u201d strategy incorporating several measures:<\/p>\n<ul class=\"wp-block-list\">\n<li>\n<strong>Full Disk Encryption<\/strong>:\u00a0Using tools like BitLocker makes the raw data on the disk unreadable without the encryption key, significantly hampering this attack.<\/li>\n<li>\n<strong>Restrict Privileges<\/strong>:\u00a0Limiting administrative access makes it harder for attackers to interact directly with disk drivers or install new malicious ones.<\/li>\n<li>\n<strong>Monitor for Raw Access<\/strong>:\u00a0Advanced monitoring with tools like Microsoft\u2019s Sysmon can be configured to detect raw disk read events (Event ID 9), though this may require careful filtering to manage alerts.<\/li>\n<li>\n<strong>Driver Vetting<\/strong>:\u00a0Organizations should actively monitor for the installation of unsigned or known-vulnerable drivers using resources like Microsoft\u2019s recommended driver blocklist.<\/li>\n<\/ul>\n<p>The researchers conclude that while the concept of raw disk access is not new, its proven effectiveness against modern EDRs highlights a significant gap in security visibility. <\/p>\n<p>As sophisticated <a href=\"https:\/\/cybersecuritynews.com\/researchers-uncovered-hacking-tools-and-techniques-discussed\/\" target=\"_blank\" rel=\"noreferrer noopener\">hacking techniques<\/a> become more accessible, organizations must understand and defend against threats that operate below the surface of the typical operating system.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 89%,rgb(169,184,195) 100%)\"><strong>Find this Story Interesting! Follow us on <a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>,\u00a0<a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>,\u00a0and\u00a0<a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener\">X<\/a>\u00a0to Get More Instant Updates<\/strong>.<\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/edr-bypass-via-disk-reads\/\">Hackers Leverage Raw Disk Reads to Bypass EDR Solutions and Access Highly Sensitive Files<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Guru Baran<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/edr-bypass-via-disk-reads\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Hackers Leverage Raw Disk Reads to Bypass EDR Solutions and Access Highly Sensitive Files A new technique that allows attackers to read highly sensitive files on Windows systems, bypassing many of the modern security tools designed to prevent such breaches. A report from Workday\u2019s Offensive Security team explains how, by reading data directly from a [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63],"tags":[130],"class_list":["post-6679","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/6679"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=6679"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/6679\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=6679"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=6679"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=6679"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}