Compliance Node Overview
MITRE ATT&CK T1680 (Local Storage Discovery) is an Enterprise Discovery technique. Adversaries may enumerate local drives, disks, and/or volumes and their attributes like total or free space and volume serial number. This can be done to prepare for ransomware-related encryption, to perform Lateral Movement, or as a precursor to Direct Volume Access. On ESXi systems, adversaries may use Hypervisor CLI commands such as `esxcli` to list storage connected to the host as well as `.vmdk` files. On Windows systems, adversaries can use `wmic logicaldisk get` to find information about local network drives. They can also use `Get-PSDrive` in PowerShell to retrieve drives and may additionally use Windows API functions such as `GetDriveType`. Linux has commands such as `parted`, `lsblk`, `fdisk`, `lshw`, and `df` that can list information about disk partitions such as size, type, fi... Affected platforms: ESXi, IaaS, Linux, macOS, Windows.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://attack.mitre.org/techniques/T1680/
SHA-256 integrity: b7a559bc114fe829abcb06d6880be8c5a320ec781554032ce6b4cad36a9f21ee
Primary Citations — 4 traced to source
- MITRE ATT&CK Technique T1680: Local Storage Discovery (https://attack.mitre.org/techniques/T1680/)
- MITRE ATT&CK Tactic TA0007: Discovery (https://attack.mitre.org/tactics/TA0007/)
+ 2 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access