Skip to content

Latest commit

 

History

History
37 lines (32 loc) · 765 Bytes

read-virtual-disk.md

File metadata and controls

37 lines (32 loc) · 765 Bytes
ID C0056
Objective(s) File System
Related ATT&CK Techniques None
Version 2.0
Created 4 December 2020
Last Modified 13 September 2023

Read Virtual Disk

Malware reads a virtual disk.

Detection

Tool: capa Mapping APIs
read virtual disk Read Virtual Disk (C0056) OpenVirtualDisk, AttachVirtualDisk, GetVirtualDiskPhysicalPath