1200KM / tool
Diskpart — Attack Tool
Diskpart is a Windows command-line utility that is used to manage the computer’s drives, which includes disks, partitions, volumes and virtual hard disks. Adversaries may abuse Diskpart to perform discovery and destructive actions on a system’s storage. For example, adversaries have been observed using Diskpart to conduct Discovery techniques to enumerate disks and volumes to gather information about the host environment, and to execute commands such as `clean all` to remove partition information and overwrite data across disks, resulting in data destruction.
Tool identity and evidence
Included because the active pinned ATT&CK object has type tool. This is an upstream classification, not an assurance of benignness or a recommendation to run it.
Aliases: Diskpart
Existing author guides
No reviewed association in this snapshot.
Primary documentation
No reviewed association in this snapshot.
Connected ecosystem references
Linked tags
Technique-specific simulations and detections
Detection links describe the associated behavior, not independently verified tool-specific signatures.
- T1059.003 · Windows Command Shell · Detection rules & anomalies
- T1082 · System Information Discovery · Detection rules & anomalies
- T1083 · File and Directory Discovery · Detection rules & anomalies
- T1222.001 · Windows Permissions · Detection rules & anomalies
- T1561.002 · Disk Structure Wipe · Detection rules & anomalies
Telemetry context
Derived from the explicitly linked TTPs; not proof of sensor coverage for this tool.
- Active Directory Object Modification · DC0066
- Command Execution · DC0064
- Drive Access · DC0054
- Drive Modification · DC0046
- Driver Load · DC0079
- File Access · DC0055
- File Creation · DC0039
- File Metadata · DC0059
- Instance Enumeration · DC0075
- Module Load · DC0016
- Process Creation · DC0032
- Script Execution · DC0029
- User Account Authentication · DC0002
- User Account Metadata · DC0013
- WMI Creation · DC0008
- Windows Registry Key Modification · DC0063
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.