Real-world descriptions of how a group, tool or campaign used a technique.
58 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1082 System Information Discovery |
GroupPlay | Play has leveraged tools to enumerate system information. |
| T1082 System Information Discovery |
GroupHEXANE | HEXANE has collected the hostname of a compromised machine. |
| T1082 System Information Discovery |
GroupDaggerfly | Daggerfly utilizes victim machine operating system information to create custom User Agent strings for subsequent command and control communication. |
| T1082 System Information Discovery |
GroupMagic Hound | Magic Hound malware has used a PowerShell command to check the victim system architecture to determine if it is an x64 machine. Other malware has obtained the OS version, UUID, and computer/host name to send to the C2 server. |
| T1082 System Information Discovery |
GroupFIN8 | FIN8 has used PowerShell Scripts to check the architecture of a compromised machine before the selection of a 32-bit or 64-bit version of a malicious .NET loader. |
| T1082 System Information Discovery |
GroupFIN13 | FIN13 has collected local host information by utilizing Windows commands `systeminfo`, `fsutil`, and `fsinfo`. FIN13 has also utilized a compromised Symantex Altiris console and LanDesk account to retrieve host information. |
| T1082 System Information Discovery |
GroupAPT19 | APT19 collected system architecture information. APT19 used an HTTP malware variant and a Port 22 malware variant to gather the hostname and CPU information from the victim’s machine. |
| T1082 System Information Discovery |
GroupShinyHunters | ShinyHunters has used the MeshCentral command-line utility meshctrl.js to collect hostnames and IDs of compromised systems. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.