Real-world descriptions of how a group, tool or campaign used a technique.
10 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1680 Local Storage Discovery |
GroupKimsuky | Kimsuky has enumerated drives. |
| T1680 Local Storage Discovery |
GroupVolt Typhoon | Volt Typhoon has discovered file system types, drive names, size, and free space on compromised systems. |
| T1680 Local Storage Discovery |
GroupPatchwork | Patchwork enumerated all available drives on the victim's machine. |
| T1680 Local Storage Discovery |
GroupTeamTNT | TeamTNT has searched for disk partition and logical volume information. |
| T1680 Local Storage Discovery |
GroupHigaisa | Higaisa collected the system volume serial number. |
| T1680 Local Storage Discovery |
GroupTropic Trooper | Tropic Trooper has detected a target system’s system volume information. |
| T1680 Local Storage Discovery |
GroupConfucius | Confucius has used a file stealer that can examine system drives, including those other than the C drive. |
| T1680 Local Storage Discovery |
GroupChimera | Chimera has used `fsutil fsinfo drives`, `systeminfo`, and `vssadmin list shadows` for system information including shadow volumes and drive information. |
| T1680 Local Storage Discovery |
GroupToddyCat | ToddyCat has collected information on bootable drives including model, vendor, and serial numbers. |
| T1680 Local Storage Discovery |
GroupLazarus Group | A Destover-like variant used by Lazarus Group collects disk space information and sends it to its C2 server. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.