Technique.View on attack.mitre.org
Adversaries may enumerate local drives, disks, and/or volumes and their attributes like total or free space and volume serial number. This can be done to prepare for ransomware-related encryption, to perform Lateral Movement, or as a precursor to Direct Volume Access.
On ESXi systems, adversaries may use Hypervisor CLI commands such as `esxcli` to list storage connected to the host as well as `.vmdk` files.
On Windows systems, adversaries can use `wmic logicaldisk get` to find information about local network drives. They can also use `Get-PSDrive` in PowerShell to retrieve drives and may additionally use Windows API functions such as `GetDriveType`.
Linux has commands such as `parted`, `lsblk`, `fdisk`, `lshw`, and `df` that can list information about disk partitions such as size, type, file system types, and free space. The command `diskutil` on MacOS can be used to list disks while `system_profiler SPStorageDataType` can additionally show information such as a volume’s mount path, file system, and the type of drive in the system.
Infrastructure as a Service (IaaS) cloud providers also have commands for storage discovery such as `describe volume` in AWS, `gcloud compute disks list` in GCP, and `az disk list` in Azure.
Rules on DetectionCode tagged with T1680.
| Used by | Procedure example |
|---|---|
| GroupChimera | Chimera has used `fsutil fsinfo drives`, `systeminfo`, and `vssadmin list shadows` for system information including shadow volumes and drive information. |
| GroupConfucius | Confucius has used a file stealer that can examine system drives, including those other than the C drive. |
| GroupHigaisa | Higaisa collected the system volume serial number. |
| GroupKimsuky | Kimsuky has enumerated drives. |
| GroupLazarus Group | A Destover-like variant used by Lazarus Group collects disk space information and sends it to its C2 server. |
| GroupPatchwork | Patchwork enumerated all available drives on the victim's machine. |
| GroupTeamTNT | TeamTNT has searched for disk partition and logical volume information. |
| GroupToddyCat | ToddyCat has collected information on bootable drives including model, vendor, and serial numbers. |
| Used by | Procedure example |
|---|---|
| MalwareAria-body | Aria-body has the ability to identify disk information on a compromised host. |
| MalwareAshTag | AshTag can use `volumeserialnumber` to enumerate volumes. |
| ToolAsyncRAT | AsyncRAT can check the disk size through the values obtained with `DeviceInfo.` |
| MalwareAttor | Attor monitors the free disk space on the system. |
| MalwareAvenger | Avenger has the ability to identify the host volume ID. |
| MalwareBabuk | Babuk can enumerate disk volumes, get disk information, and query service status. |
| MalwareBandook | Bandook can collect information about the drives available on the system. |
| MalwareBankshot | Bankshot gathers disk type and disk free space. |
| Used by | Procedure example |
|---|---|
| CampaignC0017 | During C0017, APT41 issued `ping -n 1 ((cmd /c dir c:\|findstr Number).split()[-1]+` commands to find the volume serial number of compromised systems. |
| CampaignOperation Wocao | During Operation Wocao, threat actors discovered the local disks attached to the system and their hardware information including manufacturer and model. |
| CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 used `fsutil` to check available free space before executing actions that might create large files on disk. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.