ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1680×

88 examples

TechniqueUsed byProcedure example
T1680
Local Storage Discovery
MalwareJHUHUGIT

JHUHUGIT obtains a build identifier as well as victim hard drive information from Windows registry key HKLM\SYSTEM\CurrentControlSet\Services\Disk\Enum. Another JHUHUGIT variant gathers the victim storage volume serial number and the storage device name.

T1680
Local Storage Discovery
MalwareKGH_SPY

KGH_SPY can collect drive information from a compromised host.

T1680
Local Storage Discovery
Malwaredown_new

down_new has the ability to identify the system volume information of a compromised host.

T1680
Local Storage Discovery
MalwareBlack Basta

Black Basta can enumerate volumes.

T1680
Local Storage Discovery
MalwareAttor

Attor monitors the free disk space on the system.

T1680
Local Storage Discovery
MalwareLitePower

LitePower has the ability to list local drives.

T1680
Local Storage Discovery
MalwareRyuk

Ryuk has called GetLogicalDrives to emumerate all mounted drives, and GetDriveTypeW to determine the drive type.

T1680
Local Storage Discovery
MalwareHermeticWiper

HermeticWiper can enumerate physical drives on a targeted host.

T1680
Local Storage Discovery
MalwareLockBit 2.0

LockBit 2.0 can enumerate local drive configuration.

T1680
Local Storage Discovery
MalwareZebrocy

Zebrocy collects the serial number for the storage volume C:\.

T1680
Local Storage Discovery
MalwareSampleCheck5000

SampleCheck5000 can create unique victim identifiers by using the compromised system’s volume ID.

T1680
Local Storage Discovery
MalwareREvil

REvil can identify system drive information on a compromised host.

T1680
Local Storage Discovery
MalwareRamsay

Ramsay can detect system information--including disk names, total space, and remaining space--to create a hardware profile GUID which acts as a system identifier for operators.

T1680
Local Storage Discovery
MalwareAshTag

AshTag can use `volumeserialnumber` to enumerate volumes.

T1680
Local Storage Discovery
MalwareMacMa

MacMa can collect information about a compromised computer's disk sizes.

T1680
Local Storage Discovery
MalwareFunnyDream

FunnyDream can enumerate all logical drives on a targeted machine.

T1680
Local Storage Discovery
MalwareROADSWEEP

ROADSWEEP can enumerate logical drives on targeted devices.

T1680
Local Storage Discovery
MalwareSysUpdate

SysUpdate can collect a system's drive information.

T1680
Local Storage Discovery
MalwareInnaputRAT

InnaputRAT gathers volume drive information.

T1680
Local Storage Discovery
MalwareFELIXROOT

FELIXROOT collects the victim’s volume serial number.

T1680
Local Storage Discovery
MalwarePenquin

Penquin can report the disk space of a compromised host to C2.

T1680
Local Storage Discovery
MalwareCannon

Cannon can gather drive information from the victim's machine.

T1680
Local Storage Discovery
Malwarebuild_downer

build_downer has the ability to send system volume information to C2.

T1680
Local Storage Discovery
MalwareHeyoka Backdoor

Heyoka Backdoor can enumerate drives on a compromised host.

T1680
Local Storage Discovery
MalwareOctopus

Octopus can collect system drive and disk size information.

T1680
Local Storage Discovery
MalwareKillDisk

KillDisk retrieves the hard disk name by calling the CreateFileA to \\.\PHYSICALDRIVE0 API.

T1680
Local Storage Discovery
MalwareQilin

Qilin has used `GetLogicalDrives()` and `EnumResourceW()` to locate mounted drives and shares.

T1680
Local Storage Discovery
MalwareSoreFang

SoreFang can collect disk space information on victim machines by executing Systeminfo.

T1680
Local Storage Discovery
MalwarePasam

Pasam creates a backdoor through which remote attackers can retrieve information like free disk space.

T1680
Local Storage Discovery
MalwareShadowPad

ShadowPad has discovered system information including volume serial numbers.

T1680
Local Storage Discovery
MalwareINC Ransomware

INC Ransomware can discover and mount hidden drives to encrypt them.

T1680
Local Storage Discovery
MalwareZox

Zox can enumerate attached drives.

T1680
Local Storage Discovery
MalwareSLOTHFULMEDIA

SLOTHFULMEDIA has collected disk information from a victim machine.

T1680
Local Storage Discovery
MalwareFALLCHILL

FALLCHILL can collect information about installed disks from the victim.

T1680
Local Storage Discovery
ToolSILENTTRINITY

SILENTTRINITY can collect information related to a compromised host, including a list of drives.

T1680
Local Storage Discovery
ToolAsyncRAT

AsyncRAT can check the disk size through the values obtained with `DeviceInfo.`

T1680
Local Storage Discovery
ToolCrackMapExec

CrackMapExec can enumerate the system drives and associated system name.

T1680
Local Storage Discovery
MalwareZeroCleare

ZeroCleare can use the `IOCTL_DISK_GET_DRIVE_GEOMETRY_EX`, `IOCTL_DISK_GET_DRIVE_GEOMETRY`, and `IOCTL_DISK_GET_LENGTH_INFO` system calls to compute disk size.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.