ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1082×

355 examples

TechniqueUsed byProcedure example
T1082
System Information Discovery
MalwareOceanSalt

OceanSalt can collect the computer name from the system.

T1082
System Information Discovery
MalwareBrave Prince

Brave Prince collects hard drive content and system configuration information.

T1082
System Information Discovery
MalwareMedusa Ransomware

Medusa Ransomware has collected data from the SMBIOS firmware table using `GetSystemFirmwareTable`.

T1082
System Information Discovery
MalwareAppleSeed

AppleSeed can identify the OS version of a targeted system.

T1082
System Information Discovery
MalwaremacOS.OSAMiner

macOS.OSAMiner can gather the device serial number.

T1082
System Information Discovery
MalwareNETWIRE

NETWIRE can discover and collect victim system information.

T1082
System Information Discovery
MalwareEnvyScout

EnvyScout can determine whether the ISO payload was received by a Windows or iOS device.

T1082
System Information Discovery
MalwareSslMM

SslMM sends information to its hard-coded C2, including OS version, service pack information, processor speed, system name, and OS install date.

T1082
System Information Discovery
MalwareIMAPLoader

IMAPLoader uses WMI queries to gather information about the victim machine.

T1082
System Information Discovery
MalwareGomir

Gomir collects information on infected systems such as hostname, username, CPU, and RAM information.

T1082
System Information Discovery
MalwareAria-body

Aria-body has the ability to identify the hostname, computer name, Windows version, processor speed, and machine GUID on a compromised host.

T1082
System Information Discovery
MalwareBOLDMOVE

BOLDMOVE performs system survey actions following initial execution.

T1082
System Information Discovery
MalwareCrimson

Crimson contains a command to collect the victim PC name and operating system.

T1082
System Information Discovery
MalwareDUSTTRAP

DUSTTRAP reads the value of the infected system's `HKLM\SYSTEM\Microsoft\Cryptography\MachineGUID` value.

T1082
System Information Discovery
MalwareTurian

Turian can retrieve system information including OS version, memory usage, local hostname, and system adapter information.

T1082
System Information Discovery
MalwareBADHATCH

BADHATCH can obtain current system information from a compromised machine such as the `SHELL PID`, `PSVERSION`, `HOSTNAME`, `LOGONSERVER`, `LASTBOOTUP`, OS type/version, bitness, and hostname.

T1082
System Information Discovery
MalwareMachete

Machete collects the hostname of the target computer.

T1082
System Information Discovery
MalwareAction RAT

Action RAT has the ability to collect the hostname, OS version, and OS architecture of an infected host.

T1082
System Information Discovery
MalwareAvenger

Avenger has the ability to identify the OS architecture on a compromised host.

T1082
System Information Discovery
MalwarePrikormka

A module in Prikormka collects information from the victim about Windows OS version, computer name, battery info, and physical memory.

T1082
System Information Discovery
MalwarePUBLOAD

PUBLOAD has collected and sent system information including volume serial number, computer name, and system uptime to designated C2. PUBLOAD has also used several commands executed in sequence via `cmd` in a short interval to gather system information about the infected host including `systeminfo`. PUBLOAD has decrypted shellcode that collects the computer name.

T1082
System Information Discovery
MalwareSystemBC

SystemBC has collected username , build number and serial number, then sent the information to the C2 server. SystemBC has also gathered device name, operating system, and processor type.

T1082
System Information Discovery
MalwareGootloader

Gootloader can inspect the User-Agent string in GET request header information to determine the operating system of targeted systems.

T1082
System Information Discovery
MalwarePingPull

PingPull can retrieve the hostname of a compromised host.

T1082
System Information Discovery
MalwareWellMess

WellMess can identify the computer name of a compromised host.

T1082
System Information Discovery
MalwareDropBook

DropBook has checked for the presence of Arabic language in the infected machine's settings.

T1082
System Information Discovery
MalwareWoody RAT

Woody RAT can retrieve the following information from an infected machine: OS, architecture, computer name, OS build version, and environment variables.

T1082
System Information Discovery
MalwareMafalda

Mafalda can collect the computer name of a compromised host.

T1082
System Information Discovery
MalwareKARAE

KARAE can collect system information.

T1082
System Information Discovery
MalwareSquirrelwaffle

Squirrelwaffle has gathered victim computer information and configurations.

T1082
System Information Discovery
MalwareHexEval Loader

HexEval Loader has identified the OS and MAC address of victim device through host fingerprinting scripting.

T1082
System Information Discovery
MalwareAuTo Stealer

AuTo Stealer has the ability to collect the hostname and OS information from an infected host.

T1082
System Information Discovery
MalwareShrinkLocker

ShrinkLocker uses WMI queries to gather various information about the victim machine and operating system.

T1082
System Information Discovery
MalwareHildegard

Hildegard has collected the host's OS, CPU, and memory information.

T1082
System Information Discovery
MalwareSLOWDRIFT

SLOWDRIFT collects and sends system information to its C2.

T1082
System Information Discovery
MalwareSHUTTERSPEED

SHUTTERSPEED can collect system information.

T1082
System Information Discovery
MalwareSombRAT

SombRAT can execute getinfo to enumerate the computer name and OS version of a compromised system.

T1082
System Information Discovery
MalwareFlawedAmmyy

FlawedAmmyy can collect the victim's operating system and computer name during the initial infection.

T1082
System Information Discovery
MalwareSnip3

Snip3 has the ability to query `Win32_ComputerSystem` for system information.

T1082
System Information Discovery
MalwareRifdoor

Rifdoor has the ability to identify the Windows version on the compromised host.

T1082
System Information Discovery
MalwareHOPLIGHT

HOPLIGHT has been observed collecting victim machine information like OS version.

T1082
System Information Discovery
MalwareCuckoo Stealer

Cuckoo Stealer can gather information about the OS version and hardware on compromised hosts.

T1082
System Information Discovery
MalwareMobileOrder

MobileOrder has a command to upload to its C2 server victim mobile device information, including IMEI, IMSI, SIM card serial number, phone number, Android version, and other information.

T1082
System Information Discovery
MalwareInvisiMole

InvisiMole can gather information on the OS version, computer name, DEP policy, and memory size.

T1082
System Information Discovery
MalwareNaid

Naid collects a unique identifier (UID) from a compromised host.

T1082
System Information Discovery
MalwareVolgmer

Volgmer can gather system information, the computer name, OS version, drive and serial information from the victim's machine.

T1082
System Information Discovery
MalwareWINERACK

WINERACK can gather information about the host.

T1082
System Information Discovery
MalwareZeroT

ZeroT gathers the victim's computer name, Windows version, and system language, and then sends it to its C2 server.

T1082
System Information Discovery
MalwareAcidPour

AcidPour can identify various system locations and mapped devices on Linux systems as a precursor to wiping activity.

T1082
System Information Discovery
MalwareSkidmap

Skidmap has the ability to check whether the infected system’s OS is Debian or RHEL/CentOS to determine which cryptocurrency miner it should use.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.