T1680 Local Storage Discovery — ATT&CK Technique
Adversaries may enumerate local drives, disks, and/or volumes and their attributes like total or free space and volume serial number. This can be done to prepare for ransomware-related encryption, to perform Lateral Movement, or as a precursor to Direct Volume Access. On ESXi systems, adversaries may use Hypervisor CLI commands such as `esxcli` to list storage connected to the host as well as `.vmdk` files. On Windows systems, adversaries can use `wmic logicaldisk get` to find information about local network drives. They can also use `Get-PSDrive` in PowerShell to retrieve drives and may additionally use Windows API functions such as `GetDriveType`. Linux has commands such as `parted`, `lsblk`, `fdisk`, `lshw`, and `df` that can list information about disk partitions such as size, type, file system types, and free space. The command `diskutil` on MacOS can be used to list disks while `system_profiler SPStorageDataType` can additionally show information such as a volume’s mount path, file system, and the type of drive in the system. Infrastructure as a Service (IaaS) cloud providers also have commands for storage discovery such as `describe volume` in AWS, `gcloud compute disks list` in GCP, and `az disk list` in Azure.
Malware using this technique
- SLOTHFULMEDIA
- ZeroCleare
- SUGARUSH
- Cuba
- RunningRAT
- Torisma
- yty
- macOS.OSAMiner
- BlackMould
- down_new
- SysUpdate
- Nebulae
- KillDisk
- SampleCheck5000
- DynoWiper
- Cannon
- PlugX
- DarkGate
- FELIXROOT
- LockBit 3.0
- Mongall
- Woody RAT
- AsyncRAT
- CORESHELL
- Nightdoor
- TONESHELL
- Chrommme
- Pasam
- Qilin
- Medusa Ransomware
- INC Ransomware
- Heyoka Backdoor
- Zebrocy
- Proxysvc
- Penquin
- Ryuk
- KONNI
- BlackCat
- Ramsay
- LockBit 2.0
- Ninja
- Black Basta
- Bandook
- REvil
- WhisperGate
- Sardonic
- HOPLIGHT
- InvisiMole
- HELLOKITTY
- SILENTTRINITY