ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1680
Local Storage Discovery
MalwareRoyal

Royal can use `GetLogicalDrives` to enumerate logical drives.

T1680
Local Storage Discovery
MalwareBandook

Bandook can collect information about the drives available on the system.

T1680
Local Storage Discovery
MalwareKONNI

KONNI can gather information on connected drives and disk space from the victim’s machine.

T1680
Local Storage Discovery
MalwareJHUHUGIT

JHUHUGIT obtains a build identifier as well as victim hard drive information from Windows registry key HKLM\SYSTEM\CurrentControlSet\Services\Disk\Enum. Another JHUHUGIT variant gathers the victim storage volume serial number and the storage device name.

T1680
Local Storage Discovery
MalwareKGH_SPY

KGH_SPY can collect drive information from a compromised host.

T1680
Local Storage Discovery
Malwaredown_new

down_new has the ability to identify the system volume information of a compromised host.

T1680
Local Storage Discovery
MalwareBlack Basta

Black Basta can enumerate volumes.

T1680
Local Storage Discovery
MalwareAttor

Attor monitors the free disk space on the system.

T1680
Local Storage Discovery
MalwareLitePower

LitePower has the ability to list local drives.

T1680
Local Storage Discovery
MalwareRyuk

Ryuk has called GetLogicalDrives to emumerate all mounted drives, and GetDriveTypeW to determine the drive type.

T1680
Local Storage Discovery
MalwareHermeticWiper

HermeticWiper can enumerate physical drives on a targeted host.

T1680
Local Storage Discovery
MalwareLockBit 2.0

LockBit 2.0 can enumerate local drive configuration.

T1680
Local Storage Discovery
MalwareZebrocy

Zebrocy collects the serial number for the storage volume C:\.

T1680
Local Storage Discovery
MalwareSampleCheck5000

SampleCheck5000 can create unique victim identifiers by using the compromised system’s volume ID.

T1680
Local Storage Discovery
MalwareREvil

REvil can identify system drive information on a compromised host.

T1680
Local Storage Discovery
MalwareRamsay

Ramsay can detect system information--including disk names, total space, and remaining space--to create a hardware profile GUID which acts as a system identifier for operators.

T1680
Local Storage Discovery
MalwareAshTag

AshTag can use `volumeserialnumber` to enumerate volumes.

T1680
Local Storage Discovery
MalwareMacMa

MacMa can collect information about a compromised computer's disk sizes.

T1680
Local Storage Discovery
MalwareFunnyDream

FunnyDream can enumerate all logical drives on a targeted machine.

T1680
Local Storage Discovery
MalwareROADSWEEP

ROADSWEEP can enumerate logical drives on targeted devices.

T1680
Local Storage Discovery
MalwareSysUpdate

SysUpdate can collect a system's drive information.

T1680
Local Storage Discovery
MalwareInnaputRAT

InnaputRAT gathers volume drive information.

T1680
Local Storage Discovery
MalwareFELIXROOT

FELIXROOT collects the victim’s volume serial number.

T1680
Local Storage Discovery
MalwarePenquin

Penquin can report the disk space of a compromised host to C2.

T1680
Local Storage Discovery
MalwareCannon

Cannon can gather drive information from the victim's machine.

T1680
Local Storage Discovery
Malwarebuild_downer

build_downer has the ability to send system volume information to C2.

T1680
Local Storage Discovery
MalwareHeyoka Backdoor

Heyoka Backdoor can enumerate drives on a compromised host.

T1680
Local Storage Discovery
MalwareOctopus

Octopus can collect system drive and disk size information.

T1680
Local Storage Discovery
MalwareKillDisk

KillDisk retrieves the hard disk name by calling the CreateFileA to \\.\PHYSICALDRIVE0 API.

T1680
Local Storage Discovery
MalwareQilin

Qilin has used `GetLogicalDrives()` and `EnumResourceW()` to locate mounted drives and shares.

T1680
Local Storage Discovery
MalwareSoreFang

SoreFang can collect disk space information on victim machines by executing Systeminfo.

T1680
Local Storage Discovery
MalwarePasam

Pasam creates a backdoor through which remote attackers can retrieve information like free disk space.

T1680
Local Storage Discovery
MalwareShadowPad

ShadowPad has discovered system information including volume serial numbers.

T1680
Local Storage Discovery
MalwareINC Ransomware

INC Ransomware can discover and mount hidden drives to encrypt them.

T1680
Local Storage Discovery
MalwareZox

Zox can enumerate attached drives.

T1680
Local Storage Discovery
MalwareSLOTHFULMEDIA

SLOTHFULMEDIA has collected disk information from a victim machine.

T1680
Local Storage Discovery
MalwareFALLCHILL

FALLCHILL can collect information about installed disks from the victim.

T1680
Local Storage Discovery
ToolSILENTTRINITY

SILENTTRINITY can collect information related to a compromised host, including a list of drives.

T1680
Local Storage Discovery
ToolAsyncRAT

AsyncRAT can check the disk size through the values obtained with `DeviceInfo.`

T1680
Local Storage Discovery
ToolCrackMapExec

CrackMapExec can enumerate the system drives and associated system name.

T1680
Local Storage Discovery
MalwareZeroCleare

ZeroCleare can use the `IOCTL_DISK_GET_DRIVE_GEOMETRY_EX`, `IOCTL_DISK_GET_DRIVE_GEOMETRY`, and `IOCTL_DISK_GET_LENGTH_INFO` system calls to compute disk size.

T1681
Search Threat Vendor Data
GroupUNC3886

UNC3886 has replaced indicators mentioned in open-source threat intelligence publications at times under a week after their release.

T1681
Search Threat Vendor Data
GroupContagious Interview

Contagious Interview has registered accounts with Threat Intelligence vendor services to check for reporting associated with their infrastructure and to evaluate new potential infrastructure.

T1682
Query Public AI Services
GroupKimsuky

Kimsuky has used LLMs to identify think tanks, government organizations, and experts to inform targeting for spearphishing campaigns.

T1682
Query Public AI Services
GroupAPT42

APT42 has leveraged LLMs to search for official emails to build target lists, and conduct reconnaissance on potential business partners.

T1683
Generate Content
CampaignAnthropic AI-orchestrated Campaign

During the Anthropic AI-orchestrated Campaign, the adversary utilized Claude Code to automatically generate comprehensive documentation throughout the phases of the attack, including discovered services, harvested credentials, sensitive data, exploitation techniques, and complete attack progression.

T1683.001
Written Content
GroupContagious Interview

Contagious Interview has created fake social media accounts such as LinkedIn and Telegram accounts for their targeting efforts.

T1683.001
Written Content
GroupAPT-C-36

APT-C-36 has generated email content impersonating official notifications and documents that direct victims to execute malicious payloads.

T1683.001
Written Content
GroupTeamPCP

TeamPCP has created Dune-themed GitHub repositories using stolen tokens.

T1683.001
Written Content
MalwareKali365

Kali365 has generated tailored branded phishing lures to target victims utilizing a myriad of reputable services and brands that entice users to interact with the content. Kali365 has also been enabled with AI such as Claude Sonnet that evaluates emails and generates tailored responses to facilitate BEC activities.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.