Gold Open Source
ExplorePackagesVulnerabilitiesCWEsMCP ServersScan
Login
Gold Open Source

The authoritative source for production-ready open-source components. Every package, container image, AI model, and MCP server undergoes rigorous verification for security, malware, and license compliance.

Explore Gold

  • Explore Everything
  • Packages
  • Gold Certified Packages
  • Container Images
  • AI Models
  • MCP Servers
  • Agent Skills
  • Chip Manufacturers

Security Data & Tools

  • Scan Your Dependencies
  • Trending Threats
  • Threat RSS Feeds
  • CVE Database
  • Actively Exploited (KEV)
  • SGZ Zero-Days
  • CWE Index
  • MITRE ATT&CK
  • Malicious Packages
  • Security Glossary
  • Supply-Chain Report
  • Developers (API & Badge)
  • Chrome Extension
  • Credits & Data Sources

Products

  • The Platform
  • ESSCM
  • Portal
  • TPRM
  • OSM
  • Cowork
  • Code / Runner
  • Guard

Use Cases

  • Know Your Software
  • Auto-Fix Vulnerabilities
  • Asset Discovery
  • AI Governance
  • MCP Server Security
  • Supply Chain Compliance
  • Zero-Day Discovery
  • All Use Cases

Company

  • About
  • Pricing
  • Blog
  • Documentation
  • Safeguard Academy
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 Gold Open Source. All rights reserved.

Built with care bySafeguard
Home/ATT&CK/T1680
MITRE ATT&CK Technique

T1680: Local Storage Discovery

ShareXLinkedInRedditHN

Adversaries may enumerate local drives, disks, and/or volumes and their attributes like total or free space and volume serial number. This can be done to prepare for ransomware-related encryption, to perform [Lateral Movement](https://attack.mitre.org/tactics/TA0109), or as a precursor to [Direct Volume Access](https://attack.mitre.org/techniques/T1006). On ESXi systems, adversaries may use [Hypervisor CLI](https://attack.mitre.org/techniques/T1059/012) commands such as `esxcli` to list storage connected to the host as well as `.vmdk` files.(Citation: TrendMicro)(Citation: TrendMicro ESXI Ransomware) On Windows systems, adversaries can use `wmic logicaldisk get` to find information about local network drives. They can also use `Get-PSDrive` in PowerShell to retrieve drives and may additionally use Windows API functions such as `GetDriveType`.(Citation: Trend Micro MUSTANG PANDA PUBLOAD HIUPAN SEPTEMBER 2024)(Citation: Volexity) Linux has commands such as `parted`, `lsblk`, `fdisk`, `lshw`, and `df` that can list information about disk partitions such as size, type, file system types, and free space. The command `diskutil` on MacOS can be used to list disks while `system_profiler SPStorageDataType` can additionally show information such as a volume’s mount path, file system, and the type of drive in the system. Infrastructure as a Service (IaaS) cloud providers also have commands for storage discovery such as `describe volume` in AWS, `gcloud compute disks list` in GCP, and `az disk list` in Azure.(Citation: AWS docs describe volumes)(Citation: GCP gcloud compute disks list)(Citation: azure az disk)

Tactics
Discovery
Platforms
ESXi, IaaS, Linux, macOS, Windows

▪Used by groups (10)

G0032Lazarus GroupG0040PatchworkG0081Tropic TrooperG0094KimsukyG0114ChimeraG0126HigaisaG0139TeamTNTG0142ConfuciusG1017Volt TyphoonG1022ToddyCat

▪Software using this technique (88)

S0013PlugXmalwareS0044JHUHUGITmalwareS0091EpicmalwareS0115CrimsonmalwareS0137CORESHELLmalwareS0172ReavermalwareS0181FALLCHILLmalwareS0208PasammalwareS0234BandookmalwareS0238ProxysvcmalwareS0239BankshotmalwareS0248ytymalwareS0251ZebrocymalwareS0253RunningRATmalwareS0259InnaputRATmalwareS0260InvisiMolemalwareS0263TYPEFRAMEmalwareS0265KazuarmalwareS0267FELIXROOTmalwareS0271KEYMARBLEmalwareS0340OctopusmalwareS0351CannonmalwareS0353NOKKImalwareS0356KONNImalwareS0376HOPLIGHTmalwareS0438AttormalwareS0446RyukmalwareS0448Rising SunmalwareS0456Aria-bodymalwareS0458RamsaymalwareS0471build_downermalwareS0472down_newmalwareS0473AvengermalwareS0488CrackMapExectoolS0491StrongPitymalwareS0496REvilmalwareS0516SoreFangmalwareS0520BLINDINGCANmalwareS0526KGH_SPYmalwareS0533SLOTHFULMEDIAmalwareS0564BlackMouldmalwareS0586TAINTEDSCRIBEmalwareS0587PenquinmalwareS0596ShadowPadmalwareS0607KillDiskmalwareS0616DEATHRANSOMmalwareS0617HELLOKITTYmalwareS0625CubamalwareS0630NebulaemalwareS0638BabukmalwareS0663SysUpdatemalwareS0667ChrommmemalwareS0672ZoxmalwareS0678TorismamalwareS0680LitePowermalwareS0689WhisperGatemalwareS0692SILENTTRINITYtoolS0697HermeticWipermalwareS1016MacMamalwareS1026MongallmalwareS1027Heyoka BackdoormalwareS1044FunnyDreammalwareS1048macOS.OSAMinermalwareS1049SUGARUSHmalwareS1060MafaldamalwareS1065Woody RATmalwareS1068BlackCatmalwareS1070Black BastamalwareS1073RoyalmalwareS1075KOPILUWAKmalwareS1085SardonicmalwareS1087AsyncRATtoolS1089SharpDiscomalwareS1100NinjamalwareS1111DarkGatemalwareS1139INC RansomwaremalwareS1147NightdoormalwareS1150ROADSWEEPmalwareS1151ZeroClearemalwareS1168SampleCheck5000malwareS1199LockBit 2.0malwareS1202LockBit 3.0malwareS1228PUBLOADmalwareS1239TONESHELLmalwareS1242QilinmalwareS1244Medusa RansomwaremalwareS9031AshTagmalwareS9038DynoWipermalware

▪Reference

T1680on MITRE ATT&CK

MITRE ATT&CK® is a registered trademark of The MITRE Corporation. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.