Real-world descriptions of how a group, tool or campaign used a technique.
11362 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1082 System Information Discovery |
MalwareZxxZ | ZxxZ has collected the host name and operating system product name from a compromised machine. |
| T1082 System Information Discovery |
MalwareWINDSHIELD | WINDSHIELD can gather the victim computer name. |
| T1082 System Information Discovery |
MalwareShark | Shark can collect the GUID of a targeted machine. |
| T1082 System Information Discovery |
MalwareBazar | Bazar can fingerprint architecture, computer name, and OS version on the compromised host. Bazar can also check if the Russian language is installed on the infected machine and terminate if it is found. |
| T1082 System Information Discovery |
MalwareKobalos | Kobalos can record the hostname and kernel version of the target machine. |
| T1082 System Information Discovery |
MalwareBadPatch | BadPatch collects the OS system, OS version, MAC address, and the computer name from the victim’s machine. |
| T1082 System Information Discovery |
MalwareRATANKBA | RATANKBA gathers information about the OS architecture, OS name, and OS version/Service pack. |
| T1082 System Information Discovery |
MalwareXLoader | XLoader can collect system information and supported language information from the victim machine. |
| T1082 System Information Discovery |
MalwareSOUNDBITE | SOUNDBITE is capable of gathering system information. |
| T1082 System Information Discovery |
MalwareBADCALL | BADCALL collects the computer name and host name on the compromised system. |
| T1082 System Information Discovery |
MalwareMoonWind | MoonWind can obtain the victim hostname, Windows version, RAM amount, and screen resolution. |
| T1082 System Information Discovery |
MalwareHiddenFace | HiddenFace can enumerate the hostname and username of the compromised system. |
| T1082 System Information Discovery |
MalwareHermeticWiper | HermeticWiper can determine the OS version and bitness on a targeted host. |
| T1082 System Information Discovery |
MalwareFinal1stspy | Final1stspy obtains victim Microsoft Windows version information and CPU architecture. |
| T1082 System Information Discovery |
MalwareKapeka | Kapeka utilizes WinAPI calls and registry queries to gather system information. |
| T1082 System Information Discovery |
MalwareLockBit 2.0 | LockBit 2.0 can enumerate system information including hostname and domain information. |
| T1082 System Information Discovery |
MalwareZebrocy | Zebrocy collects the OS version and computer name. Zebrocy also runs the |
| T1082 System Information Discovery |
MalwareFinFisher | FinFisher checks if the victim OS is 32 or 64-bit. |
| T1082 System Information Discovery |
MalwareSpeakUp | SpeakUp uses the |
| T1082 System Information Discovery |
MalwareLunarMail | LunarMail can capture environmental variables on compromised hosts. |
| T1082 System Information Discovery |
MalwareCadelspy | Cadelspy has the ability to discover information about the compromised host. |
| T1082 System Information Discovery |
MalwareSampleCheck5000 | SampleCheck5000 can create unique victim identifiers by using the compromised system’s computer name. |
| T1082 System Information Discovery |
MalwareSUNBURST | SUNBURST collected hostname and OS version. |
| T1082 System Information Discovery |
MalwareWingbird | Wingbird checks the victim OS version after executing to determine where to drop files based on whether the victim is 32-bit or 64-bit. |
| T1082 System Information Discovery |
MalwareHotCroissant | HotCroissant has the ability to determine if the current user is an administrator, Windows product name, processor name, screen resolution, and physical RAM of the infected host. |
| T1082 System Information Discovery |
MalwareServHelper | ServHelper will attempt to enumerate Windows version and system architecture. |
| T1082 System Information Discovery |
MalwareUnknown Logger | Unknown Logger can obtain information about the victim computer name, physical memory, country, and date. |
| T1082 System Information Discovery |
MalwareREvil | REvil can identify the username, machine name, system language, keyboard layout, and OS version on a compromised host. |
| T1082 System Information Discovery |
MalwareValak | Valak can determine the Windows version and computer name on a compromised host. |
| T1082 System Information Discovery |
MalwarePinchDuke | PinchDuke gathers system configuration information. |
| T1082 System Information Discovery |
MalwareMilan | Milan can enumerate the targeted machine's name and GUID. |
| T1082 System Information Discovery |
MalwareOSX_OCEANLOTUS.D | OSX_OCEANLOTUS.D collects processor information, memory information, computer name, hardware UUID, serial number, and operating system version. OSX_OCEANLOTUS.D has used the |
| T1082 System Information Discovery |
MalwareOilBooster | OilBooster can identify the compromised system's hostname which is used to create a unique identifier. |
| T1082 System Information Discovery |
MalwareCaddyWiper | CaddyWiper can use `DsRoleGetPrimaryDomainInformation` to determine the role of the infected machine. CaddyWiper can also halt execution if the compromised host is identified as a domain controller. |
| T1082 System Information Discovery |
MalwareCyclops Blink | Cyclops Blink has the ability to query device information. |
| T1082 System Information Discovery |
MalwareTajMahal | TajMahal has the ability to identify hardware information, the computer name, and OS information on an infected host. |
| T1082 System Information Discovery |
MalwareRaccoon Stealer | Raccoon Stealer gathers information on infected systems such as operating system, processor information, RAM, and display information. |
| T1082 System Information Discovery |
MalwareCardinal RAT | Cardinal RAT can collect the hostname, Microsoft Windows version, and processor architecture from a victim machine. |
| T1082 System Information Discovery |
MalwareBISCUIT | BISCUIT has a command to collect the processor type, operation system, computer name, and whether the system is a laptop or PC. |
| T1082 System Information Discovery |
MalwareSolar | Solar can send basic information about the infected host to C2. |
| T1082 System Information Discovery |
MalwarePisloader | Pisloader has a command to collect victim system information, including the system name and OS version. |
| T1082 System Information Discovery |
MalwareGoldenSpy | GoldenSpy has gathered operating system information. |
| T1082 System Information Discovery |
MalwareGold Dragon | Gold Dragon collects endpoint information using the |
| T1082 System Information Discovery |
MalwareAshTag | The AshTag loader and AshenOrchestrator components can collect reconnaissance data from victim machines. |
| T1082 System Information Discovery |
MalwareCarberp | Carberp has collected the operating system version from the infected system. |
| T1082 System Information Discovery |
MalwareNKAbuse | NKAbuse conducts multiple system checks and includes these in subsequent "heartbeat" messages to the malware's command and control server. |
| T1082 System Information Discovery |
MalwareRevenge RAT | Revenge RAT collects the CPU information, OS information, and system language. |
| T1082 System Information Discovery |
MalwareMacMa | MacMa can collect information about a compromised computer, including: Hardware UUID, Mac serial number, and macOS version. |
| T1082 System Information Discovery |
MalwareMore_eggs | More_eggs has the capability to gather the OS version and computer name. |
| T1082 System Information Discovery |
MalwareSysUpdate | SysUpdate can collect a system's architecture, operating system version, and hostname. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.