Real-world descriptions of how a group, tool or campaign used a technique.
355 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1082 System Information Discovery |
MalwareOceanSalt | OceanSalt can collect the computer name from the system. |
| T1082 System Information Discovery |
MalwareBrave Prince | Brave Prince collects hard drive content and system configuration information. |
| T1082 System Information Discovery |
MalwareMedusa Ransomware | Medusa Ransomware has collected data from the SMBIOS firmware table using `GetSystemFirmwareTable`. |
| T1082 System Information Discovery |
MalwareAppleSeed | AppleSeed can identify the OS version of a targeted system. |
| T1082 System Information Discovery |
MalwaremacOS.OSAMiner | macOS.OSAMiner can gather the device serial number. |
| T1082 System Information Discovery |
MalwareNETWIRE | NETWIRE can discover and collect victim system information. |
| T1082 System Information Discovery |
MalwareEnvyScout | EnvyScout can determine whether the ISO payload was received by a Windows or iOS device. |
| T1082 System Information Discovery |
MalwareSslMM | SslMM sends information to its hard-coded C2, including OS version, service pack information, processor speed, system name, and OS install date. |
| T1082 System Information Discovery |
MalwareIMAPLoader | IMAPLoader uses WMI queries to gather information about the victim machine. |
| T1082 System Information Discovery |
MalwareGomir | Gomir collects information on infected systems such as hostname, username, CPU, and RAM information. |
| T1082 System Information Discovery |
MalwareAria-body | Aria-body has the ability to identify the hostname, computer name, Windows version, processor speed, and machine GUID on a compromised host. |
| T1082 System Information Discovery |
MalwareBOLDMOVE | BOLDMOVE performs system survey actions following initial execution. |
| T1082 System Information Discovery |
MalwareCrimson | Crimson contains a command to collect the victim PC name and operating system. |
| T1082 System Information Discovery |
MalwareDUSTTRAP | DUSTTRAP reads the value of the infected system's `HKLM\SYSTEM\Microsoft\Cryptography\MachineGUID` value. |
| T1082 System Information Discovery |
MalwareTurian | Turian can retrieve system information including OS version, memory usage, local hostname, and system adapter information. |
| T1082 System Information Discovery |
MalwareBADHATCH | BADHATCH can obtain current system information from a compromised machine such as the `SHELL PID`, `PSVERSION`, `HOSTNAME`, `LOGONSERVER`, `LASTBOOTUP`, OS type/version, bitness, and hostname. |
| T1082 System Information Discovery |
MalwareMachete | Machete collects the hostname of the target computer. |
| T1082 System Information Discovery |
MalwareAction RAT | Action RAT has the ability to collect the hostname, OS version, and OS architecture of an infected host. |
| T1082 System Information Discovery |
MalwareAvenger | Avenger has the ability to identify the OS architecture on a compromised host. |
| T1082 System Information Discovery |
MalwarePrikormka | A module in Prikormka collects information from the victim about Windows OS version, computer name, battery info, and physical memory. |
| T1082 System Information Discovery |
MalwarePUBLOAD | PUBLOAD has collected and sent system information including volume serial number, computer name, and system uptime to designated C2. PUBLOAD has also used several commands executed in sequence via `cmd` in a short interval to gather system information about the infected host including `systeminfo`. PUBLOAD has decrypted shellcode that collects the computer name. |
| T1082 System Information Discovery |
MalwareSystemBC | SystemBC has collected username , build number and serial number, then sent the information to the C2 server. SystemBC has also gathered device name, operating system, and processor type. |
| T1082 System Information Discovery |
MalwareGootloader | Gootloader can inspect the User-Agent string in GET request header information to determine the operating system of targeted systems. |
| T1082 System Information Discovery |
MalwarePingPull | PingPull can retrieve the hostname of a compromised host. |
| T1082 System Information Discovery |
MalwareWellMess | WellMess can identify the computer name of a compromised host. |
| T1082 System Information Discovery |
MalwareDropBook | DropBook has checked for the presence of Arabic language in the infected machine's settings. |
| T1082 System Information Discovery |
MalwareWoody RAT | Woody RAT can retrieve the following information from an infected machine: OS, architecture, computer name, OS build version, and environment variables. |
| T1082 System Information Discovery |
MalwareMafalda | Mafalda can collect the computer name of a compromised host. |
| T1082 System Information Discovery |
MalwareKARAE | KARAE can collect system information. |
| T1082 System Information Discovery |
MalwareSquirrelwaffle | Squirrelwaffle has gathered victim computer information and configurations. |
| T1082 System Information Discovery |
MalwareHexEval Loader | HexEval Loader has identified the OS and MAC address of victim device through host fingerprinting scripting. |
| T1082 System Information Discovery |
MalwareAuTo Stealer | AuTo Stealer has the ability to collect the hostname and OS information from an infected host. |
| T1082 System Information Discovery |
MalwareShrinkLocker | ShrinkLocker uses WMI queries to gather various information about the victim machine and operating system. |
| T1082 System Information Discovery |
MalwareHildegard | Hildegard has collected the host's OS, CPU, and memory information. |
| T1082 System Information Discovery |
MalwareSLOWDRIFT | SLOWDRIFT collects and sends system information to its C2. |
| T1082 System Information Discovery |
MalwareSHUTTERSPEED | SHUTTERSPEED can collect system information. |
| T1082 System Information Discovery |
MalwareSombRAT | SombRAT can execute |
| T1082 System Information Discovery |
MalwareFlawedAmmyy | FlawedAmmyy can collect the victim's operating system and computer name during the initial infection. |
| T1082 System Information Discovery |
MalwareSnip3 | Snip3 has the ability to query `Win32_ComputerSystem` for system information. |
| T1082 System Information Discovery |
MalwareRifdoor | Rifdoor has the ability to identify the Windows version on the compromised host. |
| T1082 System Information Discovery |
MalwareHOPLIGHT | HOPLIGHT has been observed collecting victim machine information like OS version. |
| T1082 System Information Discovery |
MalwareCuckoo Stealer | Cuckoo Stealer can gather information about the OS version and hardware on compromised hosts. |
| T1082 System Information Discovery |
MalwareMobileOrder | MobileOrder has a command to upload to its C2 server victim mobile device information, including IMEI, IMSI, SIM card serial number, phone number, Android version, and other information. |
| T1082 System Information Discovery |
MalwareInvisiMole | InvisiMole can gather information on the OS version, computer name, DEP policy, and memory size. |
| T1082 System Information Discovery |
MalwareNaid | Naid collects a unique identifier (UID) from a compromised host. |
| T1082 System Information Discovery |
MalwareVolgmer | Volgmer can gather system information, the computer name, OS version, drive and serial information from the victim's machine. |
| T1082 System Information Discovery |
MalwareWINERACK | WINERACK can gather information about the host. |
| T1082 System Information Discovery |
MalwareZeroT | ZeroT gathers the victim's computer name, Windows version, and system language, and then sends it to its C2 server. |
| T1082 System Information Discovery |
MalwareAcidPour | AcidPour can identify various system locations and mapped devices on Linux systems as a precursor to wiping activity. |
| T1082 System Information Discovery |
MalwareSkidmap | Skidmap has the ability to check whether the infected system’s OS is Debian or RHEL/CentOS to determine which cryptocurrency miner it should use. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.