Real-world descriptions of how a group, tool or campaign used a technique.
11362 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1082 System Information Discovery |
MalwareBackConfig | BackConfig has the ability to gather the victim's computer name. |
| T1082 System Information Discovery |
MalwareKwampirs | Kwampirs collects OS version information such as registered owner details, manufacturer details, processor type, available storage, installed patches, hostname, version info, system date, and other system information by using the commands |
| T1082 System Information Discovery |
MalwareBoomBox | BoomBox can enumerate the hostname, domain, and IP of a compromised host. |
| T1082 System Information Discovery |
MalwareDEADEYE | DEADEYE can enumerate a victim computer's volume serial number and host name. |
| T1082 System Information Discovery |
MalwareLAMEHUG | LAMEHUG has the ability to execute Windows commands returned from C2 to gather system information. |
| T1082 System Information Discovery |
MalwareMango | Mango can collect the machine name of a compromised system which is later used as part of a unique victim identifier. |
| T1082 System Information Discovery |
MalwareInnaputRAT | InnaputRAT gathers system information. |
| T1082 System Information Discovery |
MalwareKessel | Kessel has collected the system architecture, OS version, and MAC address information. |
| T1082 System Information Discovery |
MalwareGrimAgent | GrimAgent can collect the OS, and build version on a compromised host. |
| T1082 System Information Discovery |
MalwareYAHOYAH | YAHOYAH checks for the system’s Windows OS version and hostname. |
| T1082 System Information Discovery |
MalwareLokibot | Lokibot has the ability to discover the computer name and Windows product name/version. |
| T1082 System Information Discovery |
MalwareEgregor | Egregor can perform a language check of the infected system and can query the CPU information (cupid). |
| T1082 System Information Discovery |
MalwarePoetRAT | PoetRAT has the ability to gather information about the compromised host. |
| T1082 System Information Discovery |
MalwareStealBit | StealBit can enumerate the computer name and domain membership of the compromised system. |
| T1082 System Information Discovery |
MalwareFELIXROOT | FELIXROOT collects the victim’s computer name, processor architecture, OS version, and system type. |
| T1082 System Information Discovery |
MalwareZxShell | ZxShell can collect the local hostname, operating system details, CPU speed, and total physical memory. |
| T1082 System Information Discovery |
MalwareRIFLESPINE | RIFLESPINE can collect system information after installation on infected systems. |
| T1082 System Information Discovery |
MalwareNDiskMonitor | NDiskMonitor obtains the victim computer name and encrypts the information to send over its C2 channel. |
| T1082 System Information Discovery |
MalwarePenquin | Penquin can report the file system type of a compromised host to C2. |
| T1082 System Information Discovery |
MalwareSPAWNCHIMERA | SPAWNCHIMERA has obtained system information such as release, uptime, and current time. |
| T1082 System Information Discovery |
MalwareBabyShark | BabyShark has executed the |
| T1082 System Information Discovery |
MalwareCannon | Cannon can gather system information from the victim’s machine such as the OS version, and machine name. |
| T1082 System Information Discovery |
MalwareWinnti for Windows | Winnti for Windows can determine if the OS on a compromised host is newer than Windows XP. |
| T1082 System Information Discovery |
MalwareTroll Stealer | Troll Stealer can collect local system information. |
| T1082 System Information Discovery |
MalwareMeteor | Meteor has the ability to discover the hostname of a compromised host. |
| T1082 System Information Discovery |
MalwarenjRAT | njRAT enumerates the victim operating system and computer name during the initial infection. |
| T1082 System Information Discovery |
MalwareMaze | Maze has checked the language of the infected system using the "GetUSerDefaultUILanguage" function. |
| T1082 System Information Discovery |
MalwareTURNEDUP | TURNEDUP is capable of gathering system information. |
| T1082 System Information Discovery |
MalwareChChes | ChChes collects the victim hostname, window resolution, and Microsoft Windows version. |
| T1082 System Information Discovery |
MalwareManjusaka | Manjusaka performs basic system profiling actions to fingerprint and register the victim system with the C2 controller. |
| T1082 System Information Discovery |
MalwareIceApple | The IceApple Server Variable Dumper module iterates over all server variables present for the current request and returns them to the adversary. |
| T1082 System Information Discovery |
MalwareShai-Hulud | Shai-Hulud has gathered victim system information. |
| T1082 System Information Discovery |
MalwareJPIN | JPIN can obtain system information such as OS version and disk space. |
| T1082 System Information Discovery |
MalwaremetaMain | metaMain can collect the computer name from a compromised host. |
| T1082 System Information Discovery |
MalwareSideTwist | SideTwist can collect the computer name of a targeted system. |
| T1082 System Information Discovery |
MalwareKOCTOPUS | KOCTOPUS has checked the OS version using `wmic.exe` and the `find` command. |
| T1082 System Information Discovery |
MalwareMis-Type | The initial beacon packet for Mis-Type contains the operating system version and file system of the victim. |
| T1082 System Information Discovery |
MalwareLunarWeb | LunarWeb can use WMI queries and shell commands such as systeminfo.exe to collect the operating system, BIOS version, and domain name of the targeted system. |
| T1082 System Information Discovery |
MalwareXCSSET | XCSSET identifies the macOS version and uses |
| T1082 System Information Discovery |
MalwareOctopus | Octopus can collect the computer name, OS version, and OS architecture information. |
| T1082 System Information Discovery |
MalwareQilin | Qilin can detect whether a system is running FreeBSD, VMkernel (ESXi), Nutanix AHV, or a standard Linux distribution to enable platform-specific encryption behaviors. |
| T1082 System Information Discovery |
MalwareAppleJeus | AppleJeus has collected the victim host information after infection. |
| T1082 System Information Discovery |
MalwareSoreFang | SoreFang can collect the hostname, operating system configuration, and product ID on victim machines by executing Systeminfo. |
| T1082 System Information Discovery |
MalwareSTARWHALE | STARWHALE can gather the computer name of an infected host. |
| T1082 System Information Discovery |
MalwareMirageFox | MirageFox can collect CPU and architecture information from the victim’s machine. |
| T1082 System Information Discovery |
MalwareIndustroyer | Industroyer collects the victim machine’s Windows GUID. |
| T1082 System Information Discovery |
MalwareLazyWiper | LazyWiper has used `[System.Net.Dns]::GetHostName()` and `$env:COMPUTERNAME` to enumerate the hostname of a system and determine if it is a domain controller. |
| T1082 System Information Discovery |
MalwareDownPaper | DownPaper collects the victim host name and serial number, and then sends the information to the C2 server. |
| T1082 System Information Discovery |
MalwareCozyCar | A system info module in CozyCar gathers information on the victim host’s configuration. |
| T1082 System Information Discovery |
MalwareKevin | Kevin can enumerate the OS version and hostname of a targeted machine. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.