Real-world descriptions of how a group, tool or campaign used a technique.
11362 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1082 System Information Discovery |
MalwareAgent Tesla | Agent Tesla can collect the system's computer name and also has the capability to collect information on the processor, memory, OS, and video card from the system. |
| T1082 System Information Discovery |
MalwarePasam | Pasam creates a backdoor through which remote attackers can retrieve information like hostname. |
| T1082 System Information Discovery |
MalwarePOWERSTATS | POWERSTATS can retrieve OS name/architecture and computer/domain name information from compromised hosts. |
| T1082 System Information Discovery |
MalwareLinfo | Linfo creates a backdoor through which remote attackers can retrieve system information. |
| T1082 System Information Discovery |
MalwareShadowPad | ShadowPad has discovered system information including memory status, CPU frequency, and OS versions. |
| T1082 System Information Discovery |
MalwareAstaroth | Astaroth collects the machine name and keyboard language from the system. |
| T1082 System Information Discovery |
MalwareQakBot | QakBot can collect system information including the OS version and domain on a compromised host. |
| T1082 System Information Discovery |
MalwareSYSCON | SYSCON has the ability to use Systeminfo to identify system information. |
| T1082 System Information Discovery |
MalwareGelsemium | Gelsemium can determine the operating system and whether a targeted machine has a 32 or 64 bit architecture. |
| T1082 System Information Discovery |
MalwarejRAT | jRAT collects information about the OS (version, build type, install date) as well as system up-time upon receiving a connection from a backdoor. |
| T1082 System Information Discovery |
MalwareDridex | Dridex has collected the computer name and OS architecture information from the system. |
| T1082 System Information Discovery |
MalwareOSX/Shlayer | OSX/Shlayer has collected the IOPlatformUUID, session UID, and the OS version using the command |
| T1082 System Information Discovery |
MalwareDenis | Denis collects OS information and the computer name from the victim’s machine. |
| T1082 System Information Discovery |
MalwareSplatCloak | SplatCloak has collected the Windows build number using the windows kernel API `RtlGetVersion` to determine if the response is 19000 or higher (Windows 10 version 2004 or later). |
| T1082 System Information Discovery |
MalwareComnie | Comnie collects the hostname of the victim machine. |
| T1082 System Information Discovery |
MalwareOSInfo | OSInfo discovers information about the infected machine. |
| T1082 System Information Discovery |
MalwareLizar | Lizar can collect the computer name from the machine. |
| T1082 System Information Discovery |
MalwareDtrack | Dtrack can collect the victim's computer name, hostname and adapter information to create a unique identifier. |
| T1082 System Information Discovery |
MalwareLoudMiner | LoudMiner has monitored CPU usage. |
| T1082 System Information Discovery |
MalwareAzorult | Azorult can collect the machine information, system architecture, the OS version, computer name, Windows product name, the number of CPU cores, video card information, and the system language. |
| T1082 System Information Discovery |
MalwareBACKSPACE | During its initial execution, BACKSPACE extracts operating system information from the infected host. |
| T1082 System Information Discovery |
MalwareUPPERCUT | UPPERCUT has the capability to gather the system’s hostname and OS version. |
| T1082 System Information Discovery |
MalwareADVSTORESHELL | ADVSTORESHELL can run Systeminfo to gather information about the victim. |
| T1082 System Information Discovery |
MalwareStrifeWater | StrifeWater can collect the OS version, architecture, and machine name to create a unique token for the infected host. |
| T1082 System Information Discovery |
MalwareWarzoneRAT | WarzoneRAT can collect compromised host information, including OS version, PC name, RAM size, and CPU details. |
| T1082 System Information Discovery |
MalwareSLOTHFULMEDIA | SLOTHFULMEDIA has collected system name, OS version, adapter information, and memory usage from a victim machine. |
| T1082 System Information Discovery |
MalwareFALLCHILL | FALLCHILL can collect operating system (OS) version information, processor information, and system name from the victim. |
| T1082 System Information Discovery |
MalwareXORIndex Loader | XORIndex Loader has the ability to collect the hostname, OS Username, Geolocation, and OS version of an infected host. |
| T1082 System Information Discovery |
ToolCovenant | Covenant implants can gather basic information on infected systems. |
| T1082 System Information Discovery |
ToolDiskpart | Diskpart can show information about the selected disk, partition, volume, or virtual hard disk (VHD). |
| T1082 System Information Discovery |
ToolShimRatReporter | ShimRatReporter gathered the operating system name and specific Windows version of an infected machine. |
| T1082 System Information Discovery |
ToolSILENTTRINITY | SILENTTRINITY can collect information related to a compromised host, including OS version. |
| T1082 System Information Discovery |
ToolEmpire | Empire can enumerate host system information like OS, architecture, domain name, applied patches, and more. |
| T1082 System Information Discovery |
Tooldsquery | dsquery has the ability to enumerate various information, such as the operating system and host name, for systems within a domain. |
| T1082 System Information Discovery |
ToolPoshC2 | PoshC2 contains modules, such as |
| T1082 System Information Discovery |
ToolRemcos | Remcos can collect the OS version and process architecture of compromised hosts. |
| T1082 System Information Discovery |
ToolSysteminfo | Systeminfo can be used to gather information about the operating system. |
| T1082 System Information Discovery |
Toolcmd | cmd can be used to find information about the operating system. |
| T1082 System Information Discovery |
ToolKoadic | Koadic can obtain the OS version and build, computer name, and processor architecture from a compromised host. |
| T1082 System Information Discovery |
ToolPupy | Pupy can grab a system’s information including the OS version, architecture, etc. |
| T1082 System Information Discovery |
ToolQuasarRAT | QuasarRAT can gather system information from the victim’s machine including the OS type. |
| T1082 System Information Discovery |
MalwareTeamPCP Cloud Stealer | TeamPCP Cloud Stealer has detected if it is on a developer machine by checking if the environmental variable GITHUB_ACTIONS != “true”. TeamPCP Cloud Stealer has also identified readable memory regions on CI/CD runners and enumerated system information using `hostname` and `uname-a`. |
| T1082 System Information Discovery |
MalwareMini Shai-Hulud | Mini Shai-Hulud has gathered system information of victim hosts through the use of common discovery commands to include `hostname`, `uname-a` and `printenv`. Mini Shai-Hulud has also conducted system checks of the victim device to include enumerating the system type and the number of CPUs operating on victim host. |
| T1082 System Information Discovery |
MalwareBADFLICK | BADFLICK has captured victim computer name, memory space, and CPU details. |
| T1083 File and Directory Discovery |
MalwareTrickBot | TrickBot searches the system for all of the following file extensions: .avi, .mov, .mkv, .mpeg, .mpeg4, .mp4, .mp3, .wav, .ogg, .jpeg, .jpg, .png, .bmp, .gif, .tiff, .ico, .xlsx, and .zip. It can also obtain browsing history, cookies, and plug-in information. |
| T1083 File and Directory Discovery |
MalwarePowerDuke | PowerDuke has commands to get the current directory name as well as the size of a file. It also has commands to obtain information about logical drives, drive type, and free space. |
| T1083 File and Directory Discovery |
MalwareBLINDINGCAN | BLINDINGCAN can search, read, write, move, and execute files. |
| T1083 File and Directory Discovery |
MalwareNinja | Ninja has the ability to enumerate directory content. |
| T1083 File and Directory Discovery |
MalwareQuietSieve | QuietSieve can search files on the target host by extension, including doc, docx, xls, rtf, odt, txt, jpg, pdf, rar, zip, and 7z. |
| T1083 File and Directory Discovery |
MalwareSynAck | SynAck checks its directory location in an attempt to avoid launching in a sandbox. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.