ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

11362 examples

TechniqueUsed byProcedure example
T1082
System Information Discovery
MalwareBackConfig

BackConfig has the ability to gather the victim's computer name.

T1082
System Information Discovery
MalwareKwampirs

Kwampirs collects OS version information such as registered owner details, manufacturer details, processor type, available storage, installed patches, hostname, version info, system date, and other system information by using the commands systeminfo, net config workstation, hostname, ver, set, and date /t.

T1082
System Information Discovery
MalwareBoomBox

BoomBox can enumerate the hostname, domain, and IP of a compromised host.

T1082
System Information Discovery
MalwareDEADEYE

DEADEYE can enumerate a victim computer's volume serial number and host name.

T1082
System Information Discovery
MalwareLAMEHUG

LAMEHUG has the ability to execute Windows commands returned from C2 to gather system information.

T1082
System Information Discovery
MalwareMango

Mango can collect the machine name of a compromised system which is later used as part of a unique victim identifier.

T1082
System Information Discovery
MalwareInnaputRAT

InnaputRAT gathers system information.

T1082
System Information Discovery
MalwareKessel

Kessel has collected the system architecture, OS version, and MAC address information.

T1082
System Information Discovery
MalwareGrimAgent

GrimAgent can collect the OS, and build version on a compromised host.

T1082
System Information Discovery
MalwareYAHOYAH

YAHOYAH checks for the system’s Windows OS version and hostname.

T1082
System Information Discovery
MalwareLokibot

Lokibot has the ability to discover the computer name and Windows product name/version.

T1082
System Information Discovery
MalwareEgregor

Egregor can perform a language check of the infected system and can query the CPU information (cupid).

T1082
System Information Discovery
MalwarePoetRAT

PoetRAT has the ability to gather information about the compromised host.

T1082
System Information Discovery
MalwareStealBit

StealBit can enumerate the computer name and domain membership of the compromised system.

T1082
System Information Discovery
MalwareFELIXROOT

FELIXROOT collects the victim’s computer name, processor architecture, OS version, and system type.

T1082
System Information Discovery
MalwareZxShell

ZxShell can collect the local hostname, operating system details, CPU speed, and total physical memory.

T1082
System Information Discovery
MalwareRIFLESPINE

RIFLESPINE can collect system information after installation on infected systems.

T1082
System Information Discovery
MalwareNDiskMonitor

NDiskMonitor obtains the victim computer name and encrypts the information to send over its C2 channel.

T1082
System Information Discovery
MalwarePenquin

Penquin can report the file system type of a compromised host to C2.

T1082
System Information Discovery
MalwareSPAWNCHIMERA

SPAWNCHIMERA has obtained system information such as release, uptime, and current time.

T1082
System Information Discovery
MalwareBabyShark

BabyShark has executed the ver command.

T1082
System Information Discovery
MalwareCannon

Cannon can gather system information from the victim’s machine such as the OS version, and machine name.

T1082
System Information Discovery
MalwareWinnti for Windows

Winnti for Windows can determine if the OS on a compromised host is newer than Windows XP.

T1082
System Information Discovery
MalwareTroll Stealer

Troll Stealer can collect local system information.

T1082
System Information Discovery
MalwareMeteor

Meteor has the ability to discover the hostname of a compromised host.

T1082
System Information Discovery
MalwarenjRAT

njRAT enumerates the victim operating system and computer name during the initial infection.

T1082
System Information Discovery
MalwareMaze

Maze has checked the language of the infected system using the "GetUSerDefaultUILanguage" function.

T1082
System Information Discovery
MalwareTURNEDUP

TURNEDUP is capable of gathering system information.

T1082
System Information Discovery
MalwareChChes

ChChes collects the victim hostname, window resolution, and Microsoft Windows version.

T1082
System Information Discovery
MalwareManjusaka

Manjusaka performs basic system profiling actions to fingerprint and register the victim system with the C2 controller.

T1082
System Information Discovery
MalwareIceApple

The IceApple Server Variable Dumper module iterates over all server variables present for the current request and returns them to the adversary.

T1082
System Information Discovery
MalwareShai-Hulud

Shai-Hulud has gathered victim system information.

T1082
System Information Discovery
MalwareJPIN

JPIN can obtain system information such as OS version and disk space.

T1082
System Information Discovery
MalwaremetaMain

metaMain can collect the computer name from a compromised host.

T1082
System Information Discovery
MalwareSideTwist

SideTwist can collect the computer name of a targeted system.

T1082
System Information Discovery
MalwareKOCTOPUS

KOCTOPUS has checked the OS version using `wmic.exe` and the `find` command.

T1082
System Information Discovery
MalwareMis-Type

The initial beacon packet for Mis-Type contains the operating system version and file system of the victim.

T1082
System Information Discovery
MalwareLunarWeb

LunarWeb can use WMI queries and shell commands such as systeminfo.exe to collect the operating system, BIOS version, and domain name of the targeted system.

T1082
System Information Discovery
MalwareXCSSET

XCSSET identifies the macOS version and uses ioreg to determine serial number.

T1082
System Information Discovery
MalwareOctopus

Octopus can collect the computer name, OS version, and OS architecture information.

T1082
System Information Discovery
MalwareQilin

Qilin can detect whether a system is running FreeBSD, VMkernel (ESXi), Nutanix AHV, or a standard Linux distribution to enable platform-specific encryption behaviors.

T1082
System Information Discovery
MalwareAppleJeus

AppleJeus has collected the victim host information after infection.

T1082
System Information Discovery
MalwareSoreFang

SoreFang can collect the hostname, operating system configuration, and product ID on victim machines by executing Systeminfo.

T1082
System Information Discovery
MalwareSTARWHALE

STARWHALE can gather the computer name of an infected host.

T1082
System Information Discovery
MalwareMirageFox

MirageFox can collect CPU and architecture information from the victim’s machine.

T1082
System Information Discovery
MalwareIndustroyer

Industroyer collects the victim machine’s Windows GUID.

T1082
System Information Discovery
MalwareLazyWiper

LazyWiper has used `[System.Net.Dns]::GetHostName()` and `$env:COMPUTERNAME` to enumerate the hostname of a system and determine if it is a domain controller.

T1082
System Information Discovery
MalwareDownPaper

DownPaper collects the victim host name and serial number, and then sends the information to the C2 server.

T1082
System Information Discovery
MalwareCozyCar

A system info module in CozyCar gathers information on the victim host’s configuration.

T1082
System Information Discovery
MalwareKevin

Kevin can enumerate the OS version and hostname of a targeted machine.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.