ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

11362 examples

TechniqueUsed byProcedure example
T1082
System Information Discovery
MalwareVERMIN

VERMIN collects the OS name, machine name, and architecture information.

T1082
System Information Discovery
MalwareNightdoor

Nightdoor gathers information on the victim system such as CPU and Computer name as well as device drivers.

T1082
System Information Discovery
MalwareMarkiRAT

MarkiRAT can obtain the computer name from a compromised host.

T1082
System Information Discovery
MalwarePowerShower

PowerShower has collected system information on the infected host.

T1082
System Information Discovery
MalwareKazuar

Kazuar gathers information on the system.

T1082
System Information Discovery
MalwareNavRAT

NavRAT uses systeminfo on a victim’s machine.

T1082
System Information Discovery
MalwareDarkComet

DarkComet can collect the computer name, RAM used, and operating system version from the victim’s machine.

T1082
System Information Discovery
MalwarePOORAIM

POORAIM can identify system information, including battery status.

T1082
System Information Discovery
MalwareFatDuke

FatDuke can collect the user name, Windows version, computer name, and available space on discs from a compromised host.

T1082
System Information Discovery
MalwareLucifer

Lucifer can collect the computer name, system architecture, default language, and processor frequency of a compromised host.

T1082
System Information Discovery
MalwareBlackEnergy

BlackEnergy has used Systeminfo to gather the OS version, as well as information on the system configuration, BIOS, the motherboard, and the processor.

T1082
System Information Discovery
MalwarezwShell

zwShell can obtain the victim PC name and OS version.

T1082
System Information Discovery
MalwareRising Sun

Rising Sun can detect the computer name and operating system.

T1082
System Information Discovery
MalwareChrommme

Chrommme has the ability to obtain the computer name of a compromised host.

T1082
System Information Discovery
MalwareObliqueRAT

ObliqueRAT has the ability to check for blocklisted computer names on infected endpoints.

T1082
System Information Discovery
MalwareSocGholish

SocGholish has the ability to enumerate system information including the victim computer name.

T1082
System Information Discovery
MalwareSpicyOmelette

SpicyOmelette can identify the system name of a compromised host.

T1082
System Information Discovery
MalwareXAgentOSX

XAgentOSX contains the getInstalledAPP function to run ls -la /Applications to gather what applications are installed.

T1082
System Information Discovery
MalwareGreen Lambert

Green Lambert can use `uname` to identify the operating system name, version, and processor type.

T1082
System Information Discovery
MalwareLightSpy

LightSpy's second stage implant uses the `DeviceInformation` class to collect system information, including CPU usage, battery statistics, memory allocations, screen size, etc.

T1082
System Information Discovery
MalwarePUNCHBUGGY

PUNCHBUGGY can gather system information such as computer names.

T1082
System Information Discovery
MalwareKeyBoy

KeyBoy can gather extended system information, such as information about the operating system and memory.

T1082
System Information Discovery
MalwareMiniDuke

MiniDuke can gather the hostname on a compromised machine.

T1082
System Information Discovery
MalwareAnchor

Anchor can determine the hostname and linux version on a compromised host.

T1082
System Information Discovery
MalwareDarkTortilla

DarkTortilla can obtain system information by querying the `Win32_ComputerSystem`, `Win32_BIOS`, `Win32_MotherboardDevice`, `Win32_PnPEntity`, and `Win32_DiskDrive` WMI objects.

T1082
System Information Discovery
MalwareBeaverTail

BeaverTail has been known to collect basic system information. BeaverTail has also collected data to include hostname and current timestamp prior to uploading data to the API endpoint `/uploads` on the C2 server.

T1082
System Information Discovery
MalwareROKRAT

ROKRAT can gather the hostname and the OS version to ensure it doesn’t run on a Windows XP or Windows Server 2003 systems.

T1082
System Information Discovery
MalwareCORESHELL

CORESHELL collects hostname and OS version data from the victim and sends the information to its C2 server.

T1082
System Information Discovery
MalwareRunningRAT

RunningRAT gathers the OS version and processor information.

T1082
System Information Discovery
MalwareDarkWatchman

DarkWatchman can collect the OS version, system architecture, and computer name.

T1082
System Information Discovery
MalwareDyre

Dyre has the ability to identify the computer name, OS version, and hardware configuration on a compromised host.

T1082
System Information Discovery
MalwarePlugX

PlugX has collected system information including OS version, processor information, RAM size, location, host name, IP, and screen size of the infected host.

T1082
System Information Discovery
MalwareReaver

Reaver collects system information from the victim, including CPU speed, computer name, ANSI code page, OEM code page identifier for the OS, Microsoft Windows version, and memory information.

T1082
System Information Discovery
MalwareBisonal

Bisonal has used commands and API calls to gather system information.

T1082
System Information Discovery
MalwareNOOPLDR

NOOPLDR can discover the device ID and hostname from the targeted machine to use for encryption keys.

T1082
System Information Discovery
MalwareS-Type

The initial beacon packet for S-Type contains the operating system version and file system of the victim.

T1082
System Information Discovery
MalwareLumma Stealer

Lumma Stealer has gathered various system information from victim machines.

T1082
System Information Discovery
MalwareDustySky

DustySky extracts basic information about the operating system.

T1082
System Information Discovery
MalwareRemsec

Remsec can obtain the OS version information, computer name, processor architecture, machine role, and OS edition.

T1082
System Information Discovery
MalwareExplosive

Explosive has collected the computer name from the infected host.

T1082
System Information Discovery
MalwareEpic

Epic collects the OS version, hardware information, computer name, available system memory status, and system and user language settings.

T1082
System Information Discovery
MalwareLightNeuron

LightNeuron gathers the victim computer name using the Win32 API call GetComputerName.

T1082
System Information Discovery
MalwareClambling

Clambling can discover the hostname, computer name, and Windows version of a targeted machine.

T1082
System Information Discovery
MalwarePureCrypter

PureCrypter can enumerate a targeted system's SerialNumber and Version.

T1082
System Information Discovery
MalwareAkira

Akira uses the GetSystemInfo Windows function to determine the number of processors on a victim machine.

T1082
System Information Discovery
MalwareDarkGate

DarkGate will gather various system information such as domain, display adapter description, operating system type and version, processor type, and RAM amount.

T1082
System Information Discovery
MalwareMongall

Mongall can retrieve the hostname via `gethostbyname`.

T1082
System Information Discovery
MalwareNanHaiShu

NanHaiShu can gather the victim computer name and serial number.

T1082
System Information Discovery
MalwareLockBit 3.0

LockBit 3.0 can enumerate system hostname and domain.

T1082
System Information Discovery
MalwareSVCReady

SVCReady has the ability to collect information such as computer name, computer manufacturer, BIOS, operating system, and firmware, including through the use of `systeminfo.exe`.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.