Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1680 Local Storage Discovery |
MalwareRoyal | Royal can use `GetLogicalDrives` to enumerate logical drives. |
| T1680 Local Storage Discovery |
MalwareBandook | Bandook can collect information about the drives available on the system. |
| T1680 Local Storage Discovery |
MalwareKONNI | KONNI can gather information on connected drives and disk space from the victim’s machine. |
| T1680 Local Storage Discovery |
MalwareJHUHUGIT | JHUHUGIT obtains a build identifier as well as victim hard drive information from Windows registry key |
| T1680 Local Storage Discovery |
MalwareKGH_SPY | KGH_SPY can collect drive information from a compromised host. |
| T1680 Local Storage Discovery |
Malwaredown_new | down_new has the ability to identify the system volume information of a compromised host. |
| T1680 Local Storage Discovery |
MalwareBlack Basta | Black Basta can enumerate volumes. |
| T1680 Local Storage Discovery |
MalwareAttor | Attor monitors the free disk space on the system. |
| T1680 Local Storage Discovery |
MalwareLitePower | LitePower has the ability to list local drives. |
| T1680 Local Storage Discovery |
MalwareRyuk | Ryuk has called |
| T1680 Local Storage Discovery |
MalwareHermeticWiper | HermeticWiper can enumerate physical drives on a targeted host. |
| T1680 Local Storage Discovery |
MalwareLockBit 2.0 | LockBit 2.0 can enumerate local drive configuration. |
| T1680 Local Storage Discovery |
MalwareZebrocy | Zebrocy collects the serial number for the storage volume C:\. |
| T1680 Local Storage Discovery |
MalwareSampleCheck5000 | SampleCheck5000 can create unique victim identifiers by using the compromised system’s volume ID. |
| T1680 Local Storage Discovery |
MalwareREvil | REvil can identify system drive information on a compromised host. |
| T1680 Local Storage Discovery |
MalwareRamsay | Ramsay can detect system information--including disk names, total space, and remaining space--to create a hardware profile GUID which acts as a system identifier for operators. |
| T1680 Local Storage Discovery |
MalwareAshTag | AshTag can use `volumeserialnumber` to enumerate volumes. |
| T1680 Local Storage Discovery |
MalwareMacMa | MacMa can collect information about a compromised computer's disk sizes. |
| T1680 Local Storage Discovery |
MalwareFunnyDream | FunnyDream can enumerate all logical drives on a targeted machine. |
| T1680 Local Storage Discovery |
MalwareROADSWEEP | ROADSWEEP can enumerate logical drives on targeted devices. |
| T1680 Local Storage Discovery |
MalwareSysUpdate | SysUpdate can collect a system's drive information. |
| T1680 Local Storage Discovery |
MalwareInnaputRAT | InnaputRAT gathers volume drive information. |
| T1680 Local Storage Discovery |
MalwareFELIXROOT | FELIXROOT collects the victim’s volume serial number. |
| T1680 Local Storage Discovery |
MalwarePenquin | Penquin can report the disk space of a compromised host to C2. |
| T1680 Local Storage Discovery |
MalwareCannon | Cannon can gather drive information from the victim's machine. |
| T1680 Local Storage Discovery |
Malwarebuild_downer | build_downer has the ability to send system volume information to C2. |
| T1680 Local Storage Discovery |
MalwareHeyoka Backdoor | Heyoka Backdoor can enumerate drives on a compromised host. |
| T1680 Local Storage Discovery |
MalwareOctopus | Octopus can collect system drive and disk size information. |
| T1680 Local Storage Discovery |
MalwareKillDisk | KillDisk retrieves the hard disk name by calling the |
| T1680 Local Storage Discovery |
MalwareQilin | Qilin has used `GetLogicalDrives()` and `EnumResourceW()` to locate mounted drives and shares. |
| T1680 Local Storage Discovery |
MalwareSoreFang | SoreFang can collect disk space information on victim machines by executing Systeminfo. |
| T1680 Local Storage Discovery |
MalwarePasam | Pasam creates a backdoor through which remote attackers can retrieve information like free disk space. |
| T1680 Local Storage Discovery |
MalwareShadowPad | ShadowPad has discovered system information including volume serial numbers. |
| T1680 Local Storage Discovery |
MalwareINC Ransomware | INC Ransomware can discover and mount hidden drives to encrypt them. |
| T1680 Local Storage Discovery |
MalwareZox | Zox can enumerate attached drives. |
| T1680 Local Storage Discovery |
MalwareSLOTHFULMEDIA | SLOTHFULMEDIA has collected disk information from a victim machine. |
| T1680 Local Storage Discovery |
MalwareFALLCHILL | FALLCHILL can collect information about installed disks from the victim. |
| T1680 Local Storage Discovery |
ToolSILENTTRINITY | SILENTTRINITY can collect information related to a compromised host, including a list of drives. |
| T1680 Local Storage Discovery |
ToolAsyncRAT | AsyncRAT can check the disk size through the values obtained with `DeviceInfo.` |
| T1680 Local Storage Discovery |
ToolCrackMapExec | CrackMapExec can enumerate the system drives and associated system name. |
| T1680 Local Storage Discovery |
MalwareZeroCleare | ZeroCleare can use the `IOCTL_DISK_GET_DRIVE_GEOMETRY_EX`, `IOCTL_DISK_GET_DRIVE_GEOMETRY`, and `IOCTL_DISK_GET_LENGTH_INFO` system calls to compute disk size. |
| T1681 Search Threat Vendor Data |
GroupUNC3886 | UNC3886 has replaced indicators mentioned in open-source threat intelligence publications at times under a week after their release. |
| T1681 Search Threat Vendor Data |
GroupContagious Interview | Contagious Interview has registered accounts with Threat Intelligence vendor services to check for reporting associated with their infrastructure and to evaluate new potential infrastructure. |
| T1682 Query Public AI Services |
GroupKimsuky | Kimsuky has used LLMs to identify think tanks, government organizations, and experts to inform targeting for spearphishing campaigns. |
| T1682 Query Public AI Services |
GroupAPT42 | APT42 has leveraged LLMs to search for official emails to build target lists, and conduct reconnaissance on potential business partners. |
| T1683 Generate Content |
CampaignAnthropic AI-orchestrated Campaign | During the Anthropic AI-orchestrated Campaign, the adversary utilized Claude Code to automatically generate comprehensive documentation throughout the phases of the attack, including discovered services, harvested credentials, sensitive data, exploitation techniques, and complete attack progression. |
| T1683.001 Written Content |
GroupContagious Interview | Contagious Interview has created fake social media accounts such as LinkedIn and Telegram accounts for their targeting efforts. |
| T1683.001 Written Content |
GroupAPT-C-36 | APT-C-36 has generated email content impersonating official notifications and documents that direct victims to execute malicious payloads. |
| T1683.001 Written Content |
GroupTeamPCP | TeamPCP has created Dune-themed GitHub repositories using stolen tokens. |
| T1683.001 Written Content |
MalwareKali365 | Kali365 has generated tailored branded phishing lures to target victims utilizing a myriad of reputable services and brands that entice users to interact with the content. Kali365 has also been enabled with AI such as Claude Sonnet that evaluates emails and generates tailored responses to facilitate BEC activities. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.