ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

11362 examples

TechniqueUsed byProcedure example
T1082
System Information Discovery
MalwareAgent Tesla

Agent Tesla can collect the system's computer name and also has the capability to collect information on the processor, memory, OS, and video card from the system.

T1082
System Information Discovery
MalwarePasam

Pasam creates a backdoor through which remote attackers can retrieve information like hostname.

T1082
System Information Discovery
MalwarePOWERSTATS

POWERSTATS can retrieve OS name/architecture and computer/domain name information from compromised hosts.

T1082
System Information Discovery
MalwareLinfo

Linfo creates a backdoor through which remote attackers can retrieve system information.

T1082
System Information Discovery
MalwareShadowPad

ShadowPad has discovered system information including memory status, CPU frequency, and OS versions.

T1082
System Information Discovery
MalwareAstaroth

Astaroth collects the machine name and keyboard language from the system.

T1082
System Information Discovery
MalwareQakBot

QakBot can collect system information including the OS version and domain on a compromised host.

T1082
System Information Discovery
MalwareSYSCON

SYSCON has the ability to use Systeminfo to identify system information.

T1082
System Information Discovery
MalwareGelsemium

Gelsemium can determine the operating system and whether a targeted machine has a 32 or 64 bit architecture.

T1082
System Information Discovery
MalwarejRAT

jRAT collects information about the OS (version, build type, install date) as well as system up-time upon receiving a connection from a backdoor.

T1082
System Information Discovery
MalwareDridex

Dridex has collected the computer name and OS architecture information from the system.

T1082
System Information Discovery
MalwareOSX/Shlayer

OSX/Shlayer has collected the IOPlatformUUID, session UID, and the OS version using the command sw_vers -productVersion.

T1082
System Information Discovery
MalwareDenis

Denis collects OS information and the computer name from the victim’s machine.

T1082
System Information Discovery
MalwareSplatCloak

SplatCloak has collected the Windows build number using the windows kernel API `RtlGetVersion` to determine if the response is 19000 or higher (Windows 10 version 2004 or later).

T1082
System Information Discovery
MalwareComnie

Comnie collects the hostname of the victim machine.

T1082
System Information Discovery
MalwareOSInfo

OSInfo discovers information about the infected machine.

T1082
System Information Discovery
MalwareLizar

Lizar can collect the computer name from the machine.

T1082
System Information Discovery
MalwareDtrack

Dtrack can collect the victim's computer name, hostname and adapter information to create a unique identifier.

T1082
System Information Discovery
MalwareLoudMiner

LoudMiner has monitored CPU usage.

T1082
System Information Discovery
MalwareAzorult

Azorult can collect the machine information, system architecture, the OS version, computer name, Windows product name, the number of CPU cores, video card information, and the system language.

T1082
System Information Discovery
MalwareBACKSPACE

During its initial execution, BACKSPACE extracts operating system information from the infected host.

T1082
System Information Discovery
MalwareUPPERCUT

UPPERCUT has the capability to gather the system’s hostname and OS version.

T1082
System Information Discovery
MalwareADVSTORESHELL

ADVSTORESHELL can run Systeminfo to gather information about the victim.

T1082
System Information Discovery
MalwareStrifeWater

StrifeWater can collect the OS version, architecture, and machine name to create a unique token for the infected host.

T1082
System Information Discovery
MalwareWarzoneRAT

WarzoneRAT can collect compromised host information, including OS version, PC name, RAM size, and CPU details.

T1082
System Information Discovery
MalwareSLOTHFULMEDIA

SLOTHFULMEDIA has collected system name, OS version, adapter information, and memory usage from a victim machine.

T1082
System Information Discovery
MalwareFALLCHILL

FALLCHILL can collect operating system (OS) version information, processor information, and system name from the victim.

T1082
System Information Discovery
MalwareXORIndex Loader

XORIndex Loader has the ability to collect the hostname, OS Username, Geolocation, and OS version of an infected host.

T1082
System Information Discovery
ToolCovenant

Covenant implants can gather basic information on infected systems.

T1082
System Information Discovery
ToolDiskpart

Diskpart can show information about the selected disk, partition, volume, or virtual hard disk (VHD).

T1082
System Information Discovery
ToolShimRatReporter

ShimRatReporter gathered the operating system name and specific Windows version of an infected machine.

T1082
System Information Discovery
ToolSILENTTRINITY

SILENTTRINITY can collect information related to a compromised host, including OS version.

T1082
System Information Discovery
ToolEmpire

Empire can enumerate host system information like OS, architecture, domain name, applied patches, and more.

T1082
System Information Discovery
Tooldsquery

dsquery has the ability to enumerate various information, such as the operating system and host name, for systems within a domain.

T1082
System Information Discovery
ToolPoshC2

PoshC2 contains modules, such as Get-ComputerInfo, for enumerating common system information.

T1082
System Information Discovery
ToolRemcos

Remcos can collect the OS version and process architecture of compromised hosts.

T1082
System Information Discovery
ToolSysteminfo

Systeminfo can be used to gather information about the operating system.

T1082
System Information Discovery
Toolcmd

cmd can be used to find information about the operating system.

T1082
System Information Discovery
ToolKoadic

Koadic can obtain the OS version and build, computer name, and processor architecture from a compromised host.

T1082
System Information Discovery
ToolPupy

Pupy can grab a system’s information including the OS version, architecture, etc.

T1082
System Information Discovery
ToolQuasarRAT

QuasarRAT can gather system information from the victim’s machine including the OS type.

T1082
System Information Discovery
MalwareTeamPCP Cloud Stealer

TeamPCP Cloud Stealer has detected if it is on a developer machine by checking if the environmental variable  GITHUB_ACTIONS != “true”. TeamPCP Cloud Stealer has also identified readable memory regions on CI/CD runners and enumerated system information using `hostname` and `uname-a`.

T1082
System Information Discovery
MalwareMini Shai-Hulud

Mini Shai-Hulud has gathered system information of victim hosts through the use of common discovery commands to include `hostname`, `uname-a` and `printenv`. Mini Shai-Hulud has also conducted system checks of the victim device to include enumerating the system type and the number of CPUs operating on victim host.

T1082
System Information Discovery
MalwareBADFLICK

BADFLICK has captured victim computer name, memory space, and CPU details.

T1083
File and Directory Discovery
MalwareTrickBot

TrickBot searches the system for all of the following file extensions: .avi, .mov, .mkv, .mpeg, .mpeg4, .mp4, .mp3, .wav, .ogg, .jpeg, .jpg, .png, .bmp, .gif, .tiff, .ico, .xlsx, and .zip. It can also obtain browsing history, cookies, and plug-in information.

T1083
File and Directory Discovery
MalwarePowerDuke

PowerDuke has commands to get the current directory name as well as the size of a file. It also has commands to obtain information about logical drives, drive type, and free space.

T1083
File and Directory Discovery
MalwareBLINDINGCAN

BLINDINGCAN can search, read, write, move, and execute files.

T1083
File and Directory Discovery
MalwareNinja

Ninja has the ability to enumerate directory content.

T1083
File and Directory Discovery
MalwareQuietSieve

QuietSieve can search files on the target host by extension, including doc, docx, xls, rtf, odt, txt, jpg, pdf, rar, zip, and 7z.

T1083
File and Directory Discovery
MalwareSynAck

SynAck checks its directory location in an attempt to avoid launching in a sandbox.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.