Real-world descriptions of how a group, tool or campaign used a technique.
11362 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1082 System Information Discovery |
MalwareVERMIN | VERMIN collects the OS name, machine name, and architecture information. |
| T1082 System Information Discovery |
MalwareNightdoor | Nightdoor gathers information on the victim system such as CPU and Computer name as well as device drivers. |
| T1082 System Information Discovery |
MalwareMarkiRAT | MarkiRAT can obtain the computer name from a compromised host. |
| T1082 System Information Discovery |
MalwarePowerShower | PowerShower has collected system information on the infected host. |
| T1082 System Information Discovery |
MalwareKazuar | Kazuar gathers information on the system. |
| T1082 System Information Discovery |
MalwareNavRAT | NavRAT uses |
| T1082 System Information Discovery |
MalwareDarkComet | DarkComet can collect the computer name, RAM used, and operating system version from the victim’s machine. |
| T1082 System Information Discovery |
MalwarePOORAIM | POORAIM can identify system information, including battery status. |
| T1082 System Information Discovery |
MalwareFatDuke | FatDuke can collect the user name, Windows version, computer name, and available space on discs from a compromised host. |
| T1082 System Information Discovery |
MalwareLucifer | Lucifer can collect the computer name, system architecture, default language, and processor frequency of a compromised host. |
| T1082 System Information Discovery |
MalwareBlackEnergy | BlackEnergy has used Systeminfo to gather the OS version, as well as information on the system configuration, BIOS, the motherboard, and the processor. |
| T1082 System Information Discovery |
MalwarezwShell | zwShell can obtain the victim PC name and OS version. |
| T1082 System Information Discovery |
MalwareRising Sun | Rising Sun can detect the computer name and operating system. |
| T1082 System Information Discovery |
MalwareChrommme | Chrommme has the ability to obtain the computer name of a compromised host. |
| T1082 System Information Discovery |
MalwareObliqueRAT | ObliqueRAT has the ability to check for blocklisted computer names on infected endpoints. |
| T1082 System Information Discovery |
MalwareSocGholish | SocGholish has the ability to enumerate system information including the victim computer name. |
| T1082 System Information Discovery |
MalwareSpicyOmelette | SpicyOmelette can identify the system name of a compromised host. |
| T1082 System Information Discovery |
MalwareXAgentOSX | XAgentOSX contains the getInstalledAPP function to run |
| T1082 System Information Discovery |
MalwareGreen Lambert | Green Lambert can use `uname` to identify the operating system name, version, and processor type. |
| T1082 System Information Discovery |
MalwareLightSpy | LightSpy's second stage implant uses the `DeviceInformation` class to collect system information, including CPU usage, battery statistics, memory allocations, screen size, etc. |
| T1082 System Information Discovery |
MalwarePUNCHBUGGY | PUNCHBUGGY can gather system information such as computer names. |
| T1082 System Information Discovery |
MalwareKeyBoy | KeyBoy can gather extended system information, such as information about the operating system and memory. |
| T1082 System Information Discovery |
MalwareMiniDuke | MiniDuke can gather the hostname on a compromised machine. |
| T1082 System Information Discovery |
MalwareAnchor | Anchor can determine the hostname and linux version on a compromised host. |
| T1082 System Information Discovery |
MalwareDarkTortilla | DarkTortilla can obtain system information by querying the `Win32_ComputerSystem`, `Win32_BIOS`, `Win32_MotherboardDevice`, `Win32_PnPEntity`, and `Win32_DiskDrive` WMI objects. |
| T1082 System Information Discovery |
MalwareBeaverTail | BeaverTail has been known to collect basic system information. BeaverTail has also collected data to include hostname and current timestamp prior to uploading data to the API endpoint `/uploads` on the C2 server. |
| T1082 System Information Discovery |
MalwareROKRAT | ROKRAT can gather the hostname and the OS version to ensure it doesn’t run on a Windows XP or Windows Server 2003 systems. |
| T1082 System Information Discovery |
MalwareCORESHELL | CORESHELL collects hostname and OS version data from the victim and sends the information to its C2 server. |
| T1082 System Information Discovery |
MalwareRunningRAT | RunningRAT gathers the OS version and processor information. |
| T1082 System Information Discovery |
MalwareDarkWatchman | DarkWatchman can collect the OS version, system architecture, and computer name. |
| T1082 System Information Discovery |
MalwareDyre | Dyre has the ability to identify the computer name, OS version, and hardware configuration on a compromised host. |
| T1082 System Information Discovery |
MalwarePlugX | PlugX has collected system information including OS version, processor information, RAM size, location, host name, IP, and screen size of the infected host. |
| T1082 System Information Discovery |
MalwareReaver | Reaver collects system information from the victim, including CPU speed, computer name, ANSI code page, OEM code page identifier for the OS, Microsoft Windows version, and memory information. |
| T1082 System Information Discovery |
MalwareBisonal | Bisonal has used commands and API calls to gather system information. |
| T1082 System Information Discovery |
MalwareNOOPLDR | NOOPLDR can discover the device ID and hostname from the targeted machine to use for encryption keys. |
| T1082 System Information Discovery |
MalwareS-Type | The initial beacon packet for S-Type contains the operating system version and file system of the victim. |
| T1082 System Information Discovery |
MalwareLumma Stealer | Lumma Stealer has gathered various system information from victim machines. |
| T1082 System Information Discovery |
MalwareDustySky | DustySky extracts basic information about the operating system. |
| T1082 System Information Discovery |
MalwareRemsec | Remsec can obtain the OS version information, computer name, processor architecture, machine role, and OS edition. |
| T1082 System Information Discovery |
MalwareExplosive | Explosive has collected the computer name from the infected host. |
| T1082 System Information Discovery |
MalwareEpic | Epic collects the OS version, hardware information, computer name, available system memory status, and system and user language settings. |
| T1082 System Information Discovery |
MalwareLightNeuron | LightNeuron gathers the victim computer name using the Win32 API call |
| T1082 System Information Discovery |
MalwareClambling | Clambling can discover the hostname, computer name, and Windows version of a targeted machine. |
| T1082 System Information Discovery |
MalwarePureCrypter | PureCrypter can enumerate a targeted system's SerialNumber and Version. |
| T1082 System Information Discovery |
MalwareAkira | Akira uses the |
| T1082 System Information Discovery |
MalwareDarkGate | DarkGate will gather various system information such as domain, display adapter description, operating system type and version, processor type, and RAM amount. |
| T1082 System Information Discovery |
MalwareMongall | Mongall can retrieve the hostname via `gethostbyname`. |
| T1082 System Information Discovery |
MalwareNanHaiShu | NanHaiShu can gather the victim computer name and serial number. |
| T1082 System Information Discovery |
MalwareLockBit 3.0 | LockBit 3.0 can enumerate system hostname and domain. |
| T1082 System Information Discovery |
MalwareSVCReady | SVCReady has the ability to collect information such as computer name, computer manufacturer, BIOS, operating system, and firmware, including through the use of `systeminfo.exe`. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.