ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

11362 examples

TechniqueUsed byProcedure example
T1680
Local Storage Discovery
MalwareDarkGate

DarkGate uses the Delphi methods Sysutils::DiskSize and GlobalMemoryStatusEx to collect disk size and physical memory as part of the malware's anti-analysis checks for running in a virtualized environment.

T1680
Local Storage Discovery
MalwareMongall

Mongall can identify drives on compromised hosts.

T1680
Local Storage Discovery
MalwareLockBit 3.0

LockBit 3.0 can enumerate local drive configuration.

T1680
Local Storage Discovery
MalwareTYPEFRAME

TYPEFRAME can gather the disk volume information.

T1680
Local Storage Discovery
MalwareTAINTEDSCRIBE

TAINTEDSCRIBE can use DriveList to retrieve drive information.

T1680
Local Storage Discovery
MalwareRoyal

Royal can use `GetLogicalDrives` to enumerate logical drives.

T1680
Local Storage Discovery
MalwareBandook

Bandook can collect information about the drives available on the system.

T1680
Local Storage Discovery
MalwareKONNI

KONNI can gather information on connected drives and disk space from the victim’s machine.

T1680
Local Storage Discovery
MalwareJHUHUGIT

JHUHUGIT obtains a build identifier as well as victim hard drive information from Windows registry key HKLM\SYSTEM\CurrentControlSet\Services\Disk\Enum. Another JHUHUGIT variant gathers the victim storage volume serial number and the storage device name.

T1680
Local Storage Discovery
MalwareKGH_SPY

KGH_SPY can collect drive information from a compromised host.

T1680
Local Storage Discovery
Malwaredown_new

down_new has the ability to identify the system volume information of a compromised host.

T1680
Local Storage Discovery
MalwareBlack Basta

Black Basta can enumerate volumes.

T1680
Local Storage Discovery
MalwareAttor

Attor monitors the free disk space on the system.

T1680
Local Storage Discovery
MalwareLitePower

LitePower has the ability to list local drives.

T1680
Local Storage Discovery
MalwareRyuk

Ryuk has called GetLogicalDrives to emumerate all mounted drives, and GetDriveTypeW to determine the drive type.

T1680
Local Storage Discovery
MalwareHermeticWiper

HermeticWiper can enumerate physical drives on a targeted host.

T1680
Local Storage Discovery
MalwareLockBit 2.0

LockBit 2.0 can enumerate local drive configuration.

T1680
Local Storage Discovery
MalwareZebrocy

Zebrocy collects the serial number for the storage volume C:\.

T1680
Local Storage Discovery
MalwareSampleCheck5000

SampleCheck5000 can create unique victim identifiers by using the compromised system’s volume ID.

T1680
Local Storage Discovery
MalwareREvil

REvil can identify system drive information on a compromised host.

T1680
Local Storage Discovery
MalwareRamsay

Ramsay can detect system information--including disk names, total space, and remaining space--to create a hardware profile GUID which acts as a system identifier for operators.

T1680
Local Storage Discovery
MalwareAshTag

AshTag can use `volumeserialnumber` to enumerate volumes.

T1680
Local Storage Discovery
MalwareMacMa

MacMa can collect information about a compromised computer's disk sizes.

T1680
Local Storage Discovery
MalwareFunnyDream

FunnyDream can enumerate all logical drives on a targeted machine.

T1680
Local Storage Discovery
MalwareROADSWEEP

ROADSWEEP can enumerate logical drives on targeted devices.

T1680
Local Storage Discovery
MalwareSysUpdate

SysUpdate can collect a system's drive information.

T1680
Local Storage Discovery
MalwareInnaputRAT

InnaputRAT gathers volume drive information.

T1680
Local Storage Discovery
MalwareFELIXROOT

FELIXROOT collects the victim’s volume serial number.

T1680
Local Storage Discovery
MalwarePenquin

Penquin can report the disk space of a compromised host to C2.

T1680
Local Storage Discovery
MalwareCannon

Cannon can gather drive information from the victim's machine.

T1680
Local Storage Discovery
Malwarebuild_downer

build_downer has the ability to send system volume information to C2.

T1680
Local Storage Discovery
MalwareHeyoka Backdoor

Heyoka Backdoor can enumerate drives on a compromised host.

T1680
Local Storage Discovery
MalwareOctopus

Octopus can collect system drive and disk size information.

T1680
Local Storage Discovery
MalwareKillDisk

KillDisk retrieves the hard disk name by calling the CreateFileA to \\.\PHYSICALDRIVE0 API.

T1680
Local Storage Discovery
MalwareQilin

Qilin has used `GetLogicalDrives()` and `EnumResourceW()` to locate mounted drives and shares.

T1680
Local Storage Discovery
MalwareSoreFang

SoreFang can collect disk space information on victim machines by executing Systeminfo.

T1680
Local Storage Discovery
MalwarePasam

Pasam creates a backdoor through which remote attackers can retrieve information like free disk space.

T1680
Local Storage Discovery
MalwareShadowPad

ShadowPad has discovered system information including volume serial numbers.

T1680
Local Storage Discovery
MalwareINC Ransomware

INC Ransomware can discover and mount hidden drives to encrypt them.

T1680
Local Storage Discovery
MalwareZox

Zox can enumerate attached drives.

T1680
Local Storage Discovery
MalwareSLOTHFULMEDIA

SLOTHFULMEDIA has collected disk information from a victim machine.

T1680
Local Storage Discovery
MalwareFALLCHILL

FALLCHILL can collect information about installed disks from the victim.

T1680
Local Storage Discovery
ToolSILENTTRINITY

SILENTTRINITY can collect information related to a compromised host, including a list of drives.

T1680
Local Storage Discovery
ToolAsyncRAT

AsyncRAT can check the disk size through the values obtained with `DeviceInfo.`

T1680
Local Storage Discovery
ToolCrackMapExec

CrackMapExec can enumerate the system drives and associated system name.

T1680
Local Storage Discovery
MalwareZeroCleare

ZeroCleare can use the `IOCTL_DISK_GET_DRIVE_GEOMETRY_EX`, `IOCTL_DISK_GET_DRIVE_GEOMETRY`, and `IOCTL_DISK_GET_LENGTH_INFO` system calls to compute disk size.

T1683.001
Written Content
MalwareKali365

Kali365 has generated tailored branded phishing lures to target victims utilizing a myriad of reputable services and brands that entice users to interact with the content. Kali365 has also been enabled with AI such as Claude Sonnet that evaluates emails and generates tailored responses to facilitate BEC activities.

T1684.001
Impersonation
MalwareRustyWater

RustyWater has impersonated TMCell (Altyn Asyr CJSC), the primary mobile operator in Turkmenistan, sending phishing emails with the email domain `info@tmcell`.

T1684.001
Impersonation
ToolNPPSPY

NPPSPY creates a network listener using the misspelled label logincontroll recorded to the Registry key HKLM\\SYSTEM\\CurrentControlSet\\Control\\NetworkProvider\\Order.

T1685
Disable or Modify Tools
MalwareHDoor

HDoor kills anti-virus found on the victim.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.