Local Storage Discovery

T1680

Technique.View on attack.mitre.org

About this technique

Adversaries may enumerate local drives, disks, and/or volumes and their attributes like total or free space and volume serial number. This can be done to prepare for ransomware-related encryption, to perform Lateral Movement, or as a precursor to Direct Volume Access.

On ESXi systems, adversaries may use Hypervisor CLI commands such as `esxcli` to list storage connected to the host as well as `.vmdk` files.

On Windows systems, adversaries can use `wmic logicaldisk get` to find information about local network drives. They can also use `Get-PSDrive` in PowerShell to retrieve drives and may additionally use Windows API functions such as `GetDriveType`.

Linux has commands such as `parted`, `lsblk`, `fdisk`, `lshw`, and `df` that can list information about disk partitions such as size, type, file system types, and free space. The command `diskutil` on MacOS can be used to list disks while `system_profiler SPStorageDataType` can additionally show information such as a volume’s mount path, file system, and the type of drive in the system.

Infrastructure as a Service (IaaS) cloud providers also have commands for storage discovery such as `describe volume` in AWS, `gcloud compute disks list` in GCP, and `az disk list` in Azure.

Detection rules0

Rules on DetectionCode tagged with T1680.

Sigma0

No Sigma rules are mapped to this technique yet.

Splunk0

No Splunk rules are mapped to this technique yet.

Groups10

Software88

Show 64 more

Campaigns3

Procedure examples101

Groups10

Used byProcedure example
GroupChimera

Chimera has used `fsutil fsinfo drives`, `systeminfo`, and `vssadmin list shadows` for system information including shadow volumes and drive information.

GroupConfucius

Confucius has used a file stealer that can examine system drives, including those other than the C drive.

GroupHigaisa

Higaisa collected the system volume serial number.

GroupKimsuky

Kimsuky has enumerated drives.

GroupLazarus Group

A Destover-like variant used by Lazarus Group collects disk space information and sends it to its C2 server.

GroupPatchwork

Patchwork enumerated all available drives on the victim's machine.

GroupTeamTNT

TeamTNT has searched for disk partition and logical volume information.

GroupToddyCat

ToddyCat has collected information on bootable drives including model, vendor, and serial numbers.

View all 10 groups examples

Software88

Used byProcedure example
MalwareAria-body

Aria-body has the ability to identify disk information on a compromised host.

MalwareAshTag

AshTag can use `volumeserialnumber` to enumerate volumes.

ToolAsyncRAT

AsyncRAT can check the disk size through the values obtained with `DeviceInfo.`

MalwareAttor

Attor monitors the free disk space on the system.

MalwareAvenger

Avenger has the ability to identify the host volume ID.

MalwareBabuk

Babuk can enumerate disk volumes, get disk information, and query service status.

MalwareBandook

Bandook can collect information about the drives available on the system.

MalwareBankshot

Bankshot gathers disk type and disk free space.

View all 88 software examples

Campaigns3

Used byProcedure example
CampaignC0017

During C0017, APT41 issued `ping -n 1 ((cmd /c dir c:\|findstr Number).split()[-1]+` commands to find the volume serial number of compromised systems.

CampaignOperation Wocao

During Operation Wocao, threat actors discovered the local disks attached to the system and their hardware information including manufacturer and model.

CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 used `fsutil` to check available free space before executing actions that might create large files on disk.

References7

  1. AWS docs describe volumes Open source
    AWS. (n.d.). describe-volumes. Retrieved October 20, 2025.
  2. GCP gcloud compute disks list Open source
    Google Cloud. (n.d.). gcloud compute disks list. Retrieved October 20, 2025.
  3. Trend Micro MUSTANG PANDA PUBLOAD HIUPAN SEPTEMBER 2024 Open source
    Lenart Bermejo, Sunny Lu, Ted Lee. (2024, September 9). Earth Preta Evolves its Attacks with New Malware and Strategies. Retrieved August 4, 2025.
  4. TrendMicro Open source
    Mina Naiim. (2021, May 28). DarkSide on Linux: Virtual Machines Targeted. Retrieved March 26, 2025.
  5. TrendMicro ESXI Ransomware Open source
    Junestherry Dela Cruz. (2022, January 24). Analysis and Impact of LockBit Ransomware’s First Linux and VMware ESXi Variant. Retrieved March 26, 2025.
  6. Volexity Open source
    Ankur Saini, Charlie Gardner. (2023, June 28). Charming Kitten Updates POWERSTAR with an InterPlanetary Twist. Retrieved September 25, 2025.
  7. azure az disk Open source
    Azure. (n.d.). az disk. Retrieved October 20, 2025.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.