ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

11362 examples

TechniqueUsed byProcedure example
T1082
System Information Discovery
MalwareBOLDMOVE

BOLDMOVE performs system survey actions following initial execution.

T1082
System Information Discovery
MalwareCrimson

Crimson contains a command to collect the victim PC name and operating system.

T1082
System Information Discovery
MalwareDUSTTRAP

DUSTTRAP reads the value of the infected system's `HKLM\SYSTEM\Microsoft\Cryptography\MachineGUID` value.

T1082
System Information Discovery
MalwareTurian

Turian can retrieve system information including OS version, memory usage, local hostname, and system adapter information.

T1082
System Information Discovery
MalwareBADHATCH

BADHATCH can obtain current system information from a compromised machine such as the `SHELL PID`, `PSVERSION`, `HOSTNAME`, `LOGONSERVER`, `LASTBOOTUP`, OS type/version, bitness, and hostname.

T1082
System Information Discovery
MalwareMachete

Machete collects the hostname of the target computer.

T1082
System Information Discovery
MalwareAction RAT

Action RAT has the ability to collect the hostname, OS version, and OS architecture of an infected host.

T1082
System Information Discovery
MalwareAvenger

Avenger has the ability to identify the OS architecture on a compromised host.

T1082
System Information Discovery
MalwarePrikormka

A module in Prikormka collects information from the victim about Windows OS version, computer name, battery info, and physical memory.

T1082
System Information Discovery
MalwarePUBLOAD

PUBLOAD has collected and sent system information including volume serial number, computer name, and system uptime to designated C2. PUBLOAD has also used several commands executed in sequence via `cmd` in a short interval to gather system information about the infected host including `systeminfo`. PUBLOAD has decrypted shellcode that collects the computer name.

T1082
System Information Discovery
MalwareSystemBC

SystemBC has collected username , build number and serial number, then sent the information to the C2 server. SystemBC has also gathered device name, operating system, and processor type.

T1082
System Information Discovery
MalwareGootloader

Gootloader can inspect the User-Agent string in GET request header information to determine the operating system of targeted systems.

T1082
System Information Discovery
MalwarePingPull

PingPull can retrieve the hostname of a compromised host.

T1082
System Information Discovery
MalwareWellMess

WellMess can identify the computer name of a compromised host.

T1082
System Information Discovery
MalwareDropBook

DropBook has checked for the presence of Arabic language in the infected machine's settings.

T1082
System Information Discovery
MalwareWoody RAT

Woody RAT can retrieve the following information from an infected machine: OS, architecture, computer name, OS build version, and environment variables.

T1082
System Information Discovery
MalwareMafalda

Mafalda can collect the computer name of a compromised host.

T1082
System Information Discovery
MalwareKARAE

KARAE can collect system information.

T1082
System Information Discovery
MalwareSquirrelwaffle

Squirrelwaffle has gathered victim computer information and configurations.

T1082
System Information Discovery
MalwareHexEval Loader

HexEval Loader has identified the OS and MAC address of victim device through host fingerprinting scripting.

T1082
System Information Discovery
MalwareAuTo Stealer

AuTo Stealer has the ability to collect the hostname and OS information from an infected host.

T1082
System Information Discovery
MalwareShrinkLocker

ShrinkLocker uses WMI queries to gather various information about the victim machine and operating system.

T1082
System Information Discovery
MalwareHildegard

Hildegard has collected the host's OS, CPU, and memory information.

T1082
System Information Discovery
MalwareSLOWDRIFT

SLOWDRIFT collects and sends system information to its C2.

T1082
System Information Discovery
MalwareSHUTTERSPEED

SHUTTERSPEED can collect system information.

T1082
System Information Discovery
MalwareSombRAT

SombRAT can execute getinfo to enumerate the computer name and OS version of a compromised system.

T1082
System Information Discovery
MalwareFlawedAmmyy

FlawedAmmyy can collect the victim's operating system and computer name during the initial infection.

T1082
System Information Discovery
MalwareSnip3

Snip3 has the ability to query `Win32_ComputerSystem` for system information.

T1082
System Information Discovery
MalwareRifdoor

Rifdoor has the ability to identify the Windows version on the compromised host.

T1082
System Information Discovery
MalwareHOPLIGHT

HOPLIGHT has been observed collecting victim machine information like OS version.

T1082
System Information Discovery
MalwareCuckoo Stealer

Cuckoo Stealer can gather information about the OS version and hardware on compromised hosts.

T1082
System Information Discovery
MalwareMobileOrder

MobileOrder has a command to upload to its C2 server victim mobile device information, including IMEI, IMSI, SIM card serial number, phone number, Android version, and other information.

T1082
System Information Discovery
MalwareInvisiMole

InvisiMole can gather information on the OS version, computer name, DEP policy, and memory size.

T1082
System Information Discovery
MalwareNaid

Naid collects a unique identifier (UID) from a compromised host.

T1082
System Information Discovery
MalwareVolgmer

Volgmer can gather system information, the computer name, OS version, drive and serial information from the victim's machine.

T1082
System Information Discovery
MalwareWINERACK

WINERACK can gather information about the host.

T1082
System Information Discovery
MalwareZeroT

ZeroT gathers the victim's computer name, Windows version, and system language, and then sends it to its C2 server.

T1082
System Information Discovery
MalwareAcidPour

AcidPour can identify various system locations and mapped devices on Linux systems as a precursor to wiping activity.

T1082
System Information Discovery
MalwareSkidmap

Skidmap has the ability to check whether the infected system’s OS is Debian or RHEL/CentOS to determine which cryptocurrency miner it should use.

T1082
System Information Discovery
MalwareOkrum

Okrum can collect computer name, locale information, and information about the OS and architecture.

T1082
System Information Discovery
MalwareBonadan

Bonadan has discovered the OS version, CPU model, and RAM size of the system it has been installed on.

T1082
System Information Discovery
MalwareLine Dancer

Line Dancer can gather system configuration information by running the native `show configuration` command.

T1082
System Information Discovery
MalwareNeoichor

Neoichor can collect the OS version and computer name from a compromised host.

T1082
System Information Discovery
MalwareRaspberry Robin

Raspberry Robin performs several system checks as part of anti-analysis mechanisms, including querying the operating system build number, processor vendor and type, video controller, and CPU temperature.

T1082
System Information Discovery
MalwareMispadu

Mispadu collects the OS version, computer name, and language ID.

T1082
System Information Discovery
MalwareDiavol

Diavol can collect the computer name and OS version from the system.

T1082
System Information Discovery
MalwareRustyWater

RustyWater has gathered the victim machine’s computer name.

T1082
System Information Discovery
MalwareBlackCat

BlackCat can obtain the computer name and UUID.

T1082
System Information Discovery
MalwareFysbis

Fysbis has used the command ls /etc | egrep -e"fedora\*|debian\*|gentoo\*|mandriva\*|mandrake\*|meego\*|redhat\*|lsb-\*|sun-\*|SUSE\*|release" to determine which Linux OS version is running.

T1082
System Information Discovery
MalwareIcedID

IcedID has the ability to identify the computer name and OS version on a compromised host.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.