ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1680×

10 examples

TechniqueUsed byProcedure example
T1680
Local Storage Discovery
GroupKimsuky

Kimsuky has enumerated drives.

T1680
Local Storage Discovery
GroupVolt Typhoon

Volt Typhoon has discovered file system types, drive names, size, and free space on compromised systems.

T1680
Local Storage Discovery
GroupPatchwork

Patchwork enumerated all available drives on the victim's machine.

T1680
Local Storage Discovery
GroupTeamTNT

TeamTNT has searched for disk partition and logical volume information.

T1680
Local Storage Discovery
GroupHigaisa

Higaisa collected the system volume serial number.

T1680
Local Storage Discovery
GroupTropic Trooper

Tropic Trooper has detected a target system’s system volume information.

T1680
Local Storage Discovery
GroupConfucius

Confucius has used a file stealer that can examine system drives, including those other than the C drive.

T1680
Local Storage Discovery
GroupChimera

Chimera has used `fsutil fsinfo drives`, `systeminfo`, and `vssadmin list shadows` for system information including shadow volumes and drive information.

T1680
Local Storage Discovery
GroupToddyCat

ToddyCat has collected information on bootable drives including model, vendor, and serial numbers.

T1680
Local Storage Discovery
GroupLazarus Group

A Destover-like variant used by Lazarus Group collects disk space information and sends it to its C2 server.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.