title: DN_0013_9_windows_sysmon_RawAccessRead description: > The RawAccessRead event detects when a process conducts reading operations from the drive using the \\.\ denotation loggingpolicy: - None references: - https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=90009 - https://github.com/Cyb3rWard0g/OSSEM/blob/master/data_dictionaries/windows/sysmon/event-9.md category: OS Logs platform: Windows type: Applications and Services Logs channel: Microsoft-Windows-Sysmon/Operational provider: Microsoft-Windows-Sysmon fields: - EventID - Computer - Hostname # redundant - UtcTime - ProcessGuid - ProcessId - Image - Device sample: | - - 9 2 4 9 0 0x8000000000000000 1944686 Microsoft-Windows-Sysmon/Operational atc-win-10.atc.local - 2018-03-22 20:32:22.332 {A23EAE89-C65F-5AB2-0000-0010EB030000} 4 System \Device\HarddiskVolume2