Drive

A non-volatile data storage device (hard drive, floppy disk, USB flash drive) with at least one formatted partition, typically mounted to the file system and/or assigned a drive letter[1]

ID: DS0016
Platforms: Linux, Windows, macOS
Collection Layer: Host
Contributors: Center for Threat-Informed Defense (CTID)
Version: 1.0
Created: 20 October 2021
Last Modified: 10 November 2021

Data Components

Drive: Drive Access

Opening of a data storage device with an assigned drive letter or mount point

Drive: Drive Access

Opening of a data storage device with an assigned drive letter or mount point

Domain ID Name
Enterprise T1092 Communication Through Removable Media
Enterprise T1006 Direct Volume Access
Enterprise T1561 Disk Wipe
.001 Disk Content Wipe
.002 Disk Structure Wipe

Drive: Drive Creation

Initial construction of a drive letter or mount point to a data storage device

Drive: Drive Creation

Initial construction of a drive letter or mount point to a data storage device

Domain ID Name
Enterprise T1092 Communication Through Removable Media
Enterprise T1052 Exfiltration Over Physical Medium
.001 Exfiltration over USB
Enterprise T1091 Replication Through Removable Media

Drive: Drive Modification

Changes made to a drive letter or mount point of a data storage device

Drive: Drive Modification

Changes made to a drive letter or mount point of a data storage device

Domain ID Name
Enterprise T1561 Disk Wipe
.001 Disk Content Wipe
.002 Disk Structure Wipe
Enterprise T1542 Pre-OS Boot
.003 Bootkit
Enterprise T1014 Rootkit

References