FORENSIA

ATT&CK · T1680

Local Storage Discovery

Tactics: discovery

About

Adversaries may enumerate local drives, disks, and/or volumes and their attributes like total or free space and volume serial number. This can be done to prepare for ransomware-related encryption, to perform Lateral Movement, or as a precursor to Direct Volume Access. On ESXi systems, adversaries may use Hypervisor CLI commands such as `esxcli` to list storage connected to the host as well as `.vmdk` files. On Windows systems, adversaries can use `wmic logicaldisk get` to find information about local network drives. They can also use `Get-PSDrive` in PowerShell to retrieve drives and may additionally use Windows API functions such as `GetDriveType`. Linux has commands such as `parted`, `lsblk`, `fdisk`, `lshw`, and `df` that can list information about disk partitions such as size, type, file system types, and free space. The command `diskutil` on MacOS can be used to list disks while `system_profiler SPStorageDataType` can additionally show information such as a volume’s mount path, file system, and the type of drive in the system. Infrastructure as a Service (IaaS) cloud providers also have commands for storage discovery such as `describe volume` in AWS, `gcloud compute disks list` in GCP, and `az disk list` in Azure.

Platforms: ESXi, IaaS, Linux, macOS, WindowsMITRE ATT&CK ↗

Used by actors

10 known groups

Software

88 malware/tools implement this

PlugXJHUHUGITEpicCrimsonCORESHELLReaverFALLCHILLPasamBandookProxysvcBankshotytyZebrocyRunningRATInnaputRATInvisiMoleTYPEFRAMEKazuarFELIXROOTKEYMARBLEOctopusCannonNOKKIKONNIHOPLIGHTAttorRyukRising SunAria-bodyRamsaybuild_downerdown_newAvengerCrackMapExecStrongPityREvilSoreFangBLINDINGCANKGH_SPYSLOTHFULMEDIABlackMouldTAINTEDSCRIBEPenquinShadowPadKillDiskDEATHRANSOMHELLOKITTYCubaNebulaeBabukSysUpdateChrommmeZoxTorismaLitePowerWhisperGateSILENTTRINITYHermeticWiperMacMaMongallHeyoka BackdoorFunnyDreammacOS.OSAMinerSUGARUSHMafaldaWoody RATBlackCatBlack BastaRoyalKOPILUWAKSardonicAsyncRATSharpDiscoNinjaDarkGateINC RansomwareNightdoorROADSWEEPZeroCleareSampleCheck5000LockBit 2.0LockBit 3.0PUBLOADTONESHELLQilinMedusa RansomwareAshTagDynoWiper

Corpus indicators tagged with this technique

0 indicators in the corpus carry T1680.

No corpus indicators are tagged with this technique yet.