Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1680 Local Storage Discovery |
GroupChimera | Chimera has used `fsutil fsinfo drives`, `systeminfo`, and `vssadmin list shadows` for system information including shadow volumes and drive information. |
| T1680 Local Storage Discovery |
GroupToddyCat | ToddyCat has collected information on bootable drives including model, vendor, and serial numbers. |
| T1680 Local Storage Discovery |
GroupLazarus Group | A Destover-like variant used by Lazarus Group collects disk space information and sends it to its C2 server. |
| T1680 Local Storage Discovery |
MalwareBLINDINGCAN | BLINDINGCAN has collected disk information, including type and free space available. |
| T1680 Local Storage Discovery |
MalwareNinja | Ninja can obtain information on physical drives from targeted hosts. |
| T1680 Local Storage Discovery |
MalwareProxysvc | Proxysvc collects volume information for all drives on the system. |
| T1680 Local Storage Discovery |
MalwareTorisma | Torisma can use `GetlogicalDrives` to get a bitmask of all drives available on a compromised system. It can also use `GetDriveType` to determine if a new drive is a CD-ROM drive. |
| T1680 Local Storage Discovery |
MalwareNOKKI | NOKKI can gather information on drives on the victim’s machine. |
| T1680 Local Storage Discovery |
Malwareyty | yty gathers the the serial number of the main disk volume. |
| T1680 Local Storage Discovery |
MalwareKOPILUWAK | KOPILUWAK can discover logical drive information on compromised hosts. |
| T1680 Local Storage Discovery |
MalwareSardonic | Sardonic has the ability to collect the C:\ drive serial number from a compromised machine. |
| T1680 Local Storage Discovery |
MalwareKEYMARBLE | KEYMARBLE has the capability to collect information on disk devices. |
| T1680 Local Storage Discovery |
MalwareBankshot | Bankshot gathers disk type and disk free space. |
| T1680 Local Storage Discovery |
MalwareSharpDisco | SharpDisco can use a plugin to enumerate system drives. |
| T1680 Local Storage Discovery |
MalwareStrongPity | StrongPity can identify the hard disk volume serial number on a compromised host. |
| T1680 Local Storage Discovery |
MalwareNebulae | Nebulae can discover logical drive information including the drive type, free space, and volume information. |
| T1680 Local Storage Discovery |
MalwareTONESHELL | TONESHELL has retrieved the disk serial number of the device using WMI query `SELECT volumeserialnumber FROM win32_logicaldisk where Name =’C:` to identify the victim machine. |
| T1680 Local Storage Discovery |
MalwareMedusa Ransomware | Medusa Ransomware has enumerated logical drives on infected hosts. |
| T1680 Local Storage Discovery |
MalwaremacOS.OSAMiner | macOS.OSAMiner has checked to ensure there is enough disk space using the Unix utility `df`. |
| T1680 Local Storage Discovery |
MalwareAria-body | Aria-body has the ability to identify disk information on a compromised host. |
| T1680 Local Storage Discovery |
MalwareCrimson | Crimson contains a command to collect disk drive information. |
| T1680 Local Storage Discovery |
MalwareDynoWiper | DynoWiper has used the Microsoft Windows native `GetLogicalDrives()` and `GetDriveType()` functions to enumerate all the drives visible to the system. |
| T1680 Local Storage Discovery |
MalwareAvenger | Avenger has the ability to identify the host volume ID. |
| T1680 Local Storage Discovery |
MalwarePUBLOAD | PUBLOAD has leveraged `wmic logicaldisk get` to map local network drives. |
| T1680 Local Storage Discovery |
MalwareWoody RAT | Woody RAT can retrieve information about storage drives from an infected machine. |
| T1680 Local Storage Discovery |
MalwareMafalda | Mafalda can enumerate all drives on a compromised host. |
| T1680 Local Storage Discovery |
MalwareSUGARUSH | MoonWind can obtain the number of drives on the victim machine. |
| T1680 Local Storage Discovery |
MalwareHOPLIGHT | HOPLIGHT has been observed collecting victim machine volume information. |
| T1680 Local Storage Discovery |
MalwareInvisiMole | InvisiMole can gather information on the mapped drives and system volume serial number. |
| T1680 Local Storage Discovery |
MalwareWhisperGate | WhisperGate has the ability to enumerate fixed logical drives on a targeted system. |
| T1680 Local Storage Discovery |
MalwareBlackCat | BlackCat can enumerate local drives. |
| T1680 Local Storage Discovery |
MalwareNightdoor | Nightdoor can collect information about disk drives, their total and free space, and file system type. |
| T1680 Local Storage Discovery |
MalwareKazuar | Kazuar gathers information on local drives. |
| T1680 Local Storage Discovery |
MalwareRising Sun | Rising Sun can detect drive information, including drive type, total number of bytes on disk, total number of free bytes on disk, and name of a specified volume. |
| T1680 Local Storage Discovery |
MalwareChrommme | Chrommme has the ability to list drives. |
| T1680 Local Storage Discovery |
MalwareHELLOKITTY | HELLOKITTY can enumerate logical drives on a target system. |
| T1680 Local Storage Discovery |
MalwareCORESHELL | CORESHELL collects the volume serial number from the victim and sends the information to its C2 server. |
| T1680 Local Storage Discovery |
MalwareRunningRAT | RunningRAT gathers logical drives information and volume information. |
| T1680 Local Storage Discovery |
MalwareBabuk | Babuk can enumerate disk volumes, get disk information, and query service status. |
| T1680 Local Storage Discovery |
MalwareBlackMould | BlackMould can enumerate local drives on a compromised host. |
| T1680 Local Storage Discovery |
MalwarePlugX | PlugX has collected a list of all mapped drives on the infected host. |
| T1680 Local Storage Discovery |
MalwareReaver | Reaver collects volume serial number from the victim. |
| T1680 Local Storage Discovery |
MalwareEpic | Epic collects disk space information. |
| T1680 Local Storage Discovery |
MalwareCuba | Cuba can enumerate local drives, disk type, and disk free space. |
| T1680 Local Storage Discovery |
MalwareDEATHRANSOM | DEATHRANSOM can enumerate logical drives on a target system. |
| T1680 Local Storage Discovery |
MalwareDarkGate | DarkGate uses the Delphi methods |
| T1680 Local Storage Discovery |
MalwareMongall | Mongall can identify drives on compromised hosts. |
| T1680 Local Storage Discovery |
MalwareLockBit 3.0 | LockBit 3.0 can enumerate local drive configuration. |
| T1680 Local Storage Discovery |
MalwareTYPEFRAME | TYPEFRAME can gather the disk volume information. |
| T1680 Local Storage Discovery |
MalwareTAINTEDSCRIBE | TAINTEDSCRIBE can use |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.