ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

11362 examples

TechniqueUsed byProcedure example
T1082
System Information Discovery
MalwareHydraq

Hydraq creates a backdoor through which remote attackers can retrieve information such as computer name, OS version, processor speed, memory size, and CPU speed.

T1082
System Information Discovery
MalwareSHARPSTATS

SHARPSTATS has the ability to identify the IP address, machine name, and OS of the compromised host.

T1082
System Information Discovery
MalwareFerocious

Ferocious can use GET.WORKSPACE in Microsoft Excel to determine the OS version of the compromised host.

T1082
System Information Discovery
MalwareCaterpillar WebShell

Caterpillar WebShell has a module to gather information from the compromised asset, including the computer version, computer name, IIS version, and more.

T1082
System Information Discovery
MalwareNetwalker

Netwalker can determine the system architecture it is running on to choose which version of the DLL to use.

T1082
System Information Discovery
MalwareElise

Elise executes systeminfo after initial communication is made to the remote server.

T1082
System Information Discovery
MalwareLatrodectus

Latrodectus can gather operating system information.

T1082
System Information Discovery
MalwareSaint Bot

Saint Bot can identify the OS version, CPU, and other details from a victim's machine.

T1082
System Information Discovery
MalwarePay2Key

Pay2Key has the ability to gather the hostname of the victim machine.

T1082
System Information Discovery
MalwareChaes

Chaes has collected system information, including the machine name and OS version.

T1082
System Information Discovery
MalwareLODEINFO

LODEINFO can disover machine information including OS architecture, the ANSI code page (ACP) identifier, and hostname.

T1082
System Information Discovery
MalwareCharmPower

CharmPower can enumerate the OS version and computer name on a targeted system.

T1082
System Information Discovery
MalwareBundlore

Bundlore will enumerate the macOS version to determine which follow-on behaviors to execute using /usr/bin/sw_vers -productVersion.

T1082
System Information Discovery
MalwareEVILNUM

EVILNUM can obtain the computer name from the victim's system.

T1082
System Information Discovery
MalwareKOMPROGO

KOMPROGO is capable of retrieving information about the infected system.

T1082
System Information Discovery
MalwareSMOKEDHAM

SMOKEDHAM has used the systeminfo command on a compromised host.

T1082
System Information Discovery
MalwareSagerunex

Sagerunex gathers information from the infected system such as hostname.

T1082
System Information Discovery
MalwareSys10

Sys10 collects the computer name, OS versioning information, and OS install date and sends the information to the C2.

T1082
System Information Discovery
MalwareRoyal

Royal can use `GetNativeSystemInfo` to enumerate system processors.

T1082
System Information Discovery
MalwareGlassWorm

GlassWorm has the ability to check the OS of the victim host. GlassWorm has checked whether the OS platform value includes `darwin` prior to execution of macOS specific scripts.

T1082
System Information Discovery
MalwareUroburos

Uroburos has the ability to gather basic system information and run the POSIX API `gethostbyname`.

T1082
System Information Discovery
MalwareMetamorfo

Metamorfo has collected the hostname and operating system version from the compromised host.

T1082
System Information Discovery
MalwareTrojan.Karagany

Trojan.Karagany can capture information regarding the victim's OS, security, and hardware configuration.

T1082
System Information Discovery
MalwarePipeMon

PipeMon can collect and send OS version and computer name as a part of its C2 beacon.

T1082
System Information Discovery
MalwareMagicRAT

MagicRAT collects basic system information from victim machines.

T1082
System Information Discovery
MalwareKONNI

KONNI can gather the OS version, architecture information, hostname, and RAM size information from the victim’s machine and has used cmd /c systeminfo command to get a snapshot of the current system state of the target machine.

T1082
System Information Discovery
MalwareT9000

T9000 gathers and beacons the operating system build number and CPU Architecture (32-bit/64-bit) during installation.

T1082
System Information Discovery
Malwaregh0st RAT

gh0st RAT has gathered system architecture, processor, OS configuration, and installed hardware information.

T1082
System Information Discovery
MalwareShamoon

Shamoon obtains the victim's operating system version and keyboard layout and sends the information to the C2 server.

T1082
System Information Discovery
MalwareMoleNet

MoleNet can collect information about the about the system.

T1082
System Information Discovery
MalwareBLUELIGHT

BLUELIGHT has collected the computer name and OS version from victim machines.

T1082
System Information Discovery
MalwareIxeshe

Ixeshe collects the computer name of the victim's system during the initial infection.

T1082
System Information Discovery
MalwareMicropsia

Micropsia gathers the hostname and OS version from the victim’s machine.

T1082
System Information Discovery
MalwareKerrdown

Kerrdown has the ability to determine if the compromised host is running a 32 or 64 bit OS architecture.

T1082
System Information Discovery
MalwareRedLine Stealer

RedLine Stealer can collect information about the local system.

T1082
System Information Discovery
MalwareBlack Basta

Black Basta can collect system boot configuration and CPU information.

T1082
System Information Discovery
MalwareStoneDrill

StoneDrill has the capability to discover the system OS, Windows version, architecture and environment.

T1082
System Information Discovery
MalwareOopsIE

OopsIE checks for information on the CPU fan, temperature, mouse, hard disk, and motherboard as part of its anti-VM checks.

T1082
System Information Discovery
Malware4H RAT

4H RAT sends an OS version identifier in its beacons.

T1082
System Information Discovery
MalwareRogueRobin

RogueRobin gathers BIOS versions and manufacturers, the number of CPU cores, the total physical memory, and the computer name.

T1082
System Information Discovery
MalwareLitePower

LitePower has the ability to enumerate the OS architecture.

T1082
System Information Discovery
MalwareStreamEx

StreamEx has the ability to enumerate system information.

T1082
System Information Discovery
MalwareSDBbot

SDBbot has the ability to identify the OS version, OS bit information and computer name.

T1082
System Information Discovery
MalwareRTM

RTM can obtain the computer name, OS version, and default language identifier.

T1082
System Information Discovery
MalwareDerusbi

Derusbi gathers the name of the local host, version of GNU Compiler Collection (GCC), and the system information about the CPU, machine, and operating system.

T1082
System Information Discovery
MalwareBlackByte Ransomware

BlackByte Ransomware gathers victim system information to generate a unique victim identifier.

T1082
System Information Discovery
MalwareSodaMaster

SodaMaster can enumerate the host name and OS version on a target system.

T1082
System Information Discovery
MalwareStrelaStealer

StrelaStealer variants collect victim system information for exfiltration.

T1082
System Information Discovery
MalwareGrandoreiro

Grandoreiro can collect the computer name and OS version from a compromised host.

T1082
System Information Discovery
MalwareLiteDuke

LiteDuke can enumerate the CPUID and BIOS version on a compromised system.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.