ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1082×

58 examples

TechniqueUsed byProcedure example
T1082
System Information Discovery
GroupPlay

Play has leveraged tools to enumerate system information.

T1082
System Information Discovery
GroupHEXANE

HEXANE has collected the hostname of a compromised machine.

T1082
System Information Discovery
GroupDaggerfly

Daggerfly utilizes victim machine operating system information to create custom User Agent strings for subsequent command and control communication.

T1082
System Information Discovery
GroupMagic Hound

Magic Hound malware has used a PowerShell command to check the victim system architecture to determine if it is an x64 machine. Other malware has obtained the OS version, UUID, and computer/host name to send to the C2 server.

T1082
System Information Discovery
GroupFIN8

FIN8 has used PowerShell Scripts to check the architecture of a compromised machine before the selection of a 32-bit or 64-bit version of a malicious .NET loader.

T1082
System Information Discovery
GroupFIN13

FIN13 has collected local host information by utilizing Windows commands `systeminfo`, `fsutil`, and `fsinfo`. FIN13 has also utilized a compromised Symantex Altiris console and LanDesk account to retrieve host information.

T1082
System Information Discovery
GroupAPT19

APT19 collected system architecture information. APT19 used an HTTP malware variant and a Port 22 malware variant to gather the hostname and CPU information from the victim’s machine.

T1082
System Information Discovery
GroupShinyHunters

ShinyHunters has used the MeshCentral command-line utility meshctrl.js to collect hostnames and IDs of compromised systems.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.