{"id":"T1680","name":"Local Storage Discovery","url":"https://attack.mitre.org/techniques/T1680","tactics":["discovery"],"platforms":["ESXi","IaaS","Linux","macOS","Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0188","stix_id":"x-mitre-detection-strategy--8c3d7757-f3ab-4c1d-95e1-f712cdecd5a3","name":"Local Storage Discovery via Drive Enumeration and Filesystem Probing","url":"https://attack.mitre.org/detectionstrategies/DET0188","analytics":[{"id":"AN0536","stix_id":"x-mitre-analytic--9ffd3332-fcc0-440d-b717-ef98e140c543","name":"Analytic 0536","description":"Drive enumeration using PowerShell (`Get-PSDrive`), `wmic logicaldisk`, or Win32 API indicative of local volume enumeration by non-admin users or executed outside of baseline system inventory scripts.","url":"https://attack.mitre.org/detectionstrategies/DET0188#AN0536","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Sysmon","channel":"EventCode=1","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"wineventlog-sysmon"}],"mutable_elements":[{"field":"user_context","description":"Non-system accounts performing drive enumeration may be higher fidelity indicators"},{"field":"parent_process_name","description":"Baseline parent-child process lineage can help distinguish admin tools from malicious scripts"}],"live":true,"detection_strategies":["DET0188"],"techniques":["T1680"]},{"id":"AN0537","stix_id":"x-mitre-analytic--1a7052d7-84f1-4116-bdb1-49bbe8709e3d","name":"Analytic 0537","description":"Abnormal use of `lsblk`, `fdisk -l`, `lshw -class disk`, or `parted` by non-admin users or within non-interactive shells suggests suspicious disk enumeration activity.","url":"https://attack.mitre.org/detectionstrategies/DET0188#AN0537","platforms":["Linux"],"log_source_references":[{"name":"auditd:SYSCALL","channel":"execve call with argv matching known disk enumeration commands (lsblk, parted, fdisk)","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"auditd-syscall"},{"name":"auditd:EXECVE","channel":"command line arguments containing lsblk, fdisk, parted","data_component":"DC0064","data_component_name":"Command Execution","log_source_slug":"auditd-execve"}],"mutable_elements":[{"field":"TTY_type","description":"Detection can exclude interactive TTY sessions to reduce false positives from admin usage"},{"field":"shell_parent","description":"Differentiate between interactive user shells vs. script-based execution"}],"live":true,"detection_strategies":["DET0188"],"techniques":["T1680"]},{"id":"AN0538","stix_id":"x-mitre-analytic--a98fc9c5-9c4c-47c5-a773-d68b523c7304","name":"Analytic 0538","description":"Disk enumeration via `diskutil list` or `system_profiler SPStorageDataType` run outside of user login or not associated with system inventory tools","url":"https://attack.mitre.org/detectionstrategies/DET0188#AN0538","platforms":["macOS"],"log_source_references":[{"name":"macos:unifiedlog","channel":"process launch of diskutil or system_profiler with SPStorageDataType","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"macos-unifiedlog"},{"name":"macos:unifiedlog","channel":"log messages related to disk enumeration context or Terminal session","data_component":"DC0064","data_component_name":"Command Execution","log_source_slug":"macos-unifiedlog"}],"mutable_elements":[{"field":"launch_agent_context","description":"Unexpected use of disk enumeration tools from GUI apps or LaunchAgents may indicate abuse"},{"field":"volume_name_filter","description":"Filter known baseline volume names or identifiers used by common device configurations"}],"live":true,"detection_strategies":["DET0188"],"techniques":["T1680"]},{"id":"AN0539","stix_id":"x-mitre-analytic--478e6298-d012-4337-b2ed-0f8d4909ee05","name":"Analytic 0539","description":"Use of `esxcli storage` or `vim-cmd vmsvc/getallvms` by unusual sessions or through interactive shells unrelated to administrative maintenance tasks.","url":"https://attack.mitre.org/detectionstrategies/DET0188#AN0539","platforms":["ESXi"],"log_source_references":[{"name":"esxi:hostd","channel":"execution of esxcli with args matching 'storage', 'filesystem', 'core device list'","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"esxi-hostd"},{"name":"esxi:auth","channel":"interactive shell or SSH access preceding storage enumeration","data_component":"DC0002","data_component_name":"User Account Authentication","log_source_slug":"esxi-auth"}],"mutable_elements":[{"field":"ssh_source_ip","description":"Restrict alerts to unexpected remote sessions accessing host storage commands"},{"field":"esxcli_command_scope","description":"Tailor detection based on subcommands more likely to be abused"}],"live":true,"detection_strategies":["DET0188"],"techniques":["T1680"]}],"live":true,"version":"1.0","techniques":["T1680"]}],"sigma_rules":[],"kev_cves":[],"_built":"2026-08-24 19:45 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}