ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1082×

355 examples

TechniqueUsed byProcedure example
T1082
System Information Discovery
MalwareOkrum

Okrum can collect computer name, locale information, and information about the OS and architecture.

T1082
System Information Discovery
MalwareBonadan

Bonadan has discovered the OS version, CPU model, and RAM size of the system it has been installed on.

T1082
System Information Discovery
MalwareLine Dancer

Line Dancer can gather system configuration information by running the native `show configuration` command.

T1082
System Information Discovery
MalwareNeoichor

Neoichor can collect the OS version and computer name from a compromised host.

T1082
System Information Discovery
MalwareRaspberry Robin

Raspberry Robin performs several system checks as part of anti-analysis mechanisms, including querying the operating system build number, processor vendor and type, video controller, and CPU temperature.

T1082
System Information Discovery
MalwareMispadu

Mispadu collects the OS version, computer name, and language ID.

T1082
System Information Discovery
MalwareDiavol

Diavol can collect the computer name and OS version from the system.

T1082
System Information Discovery
MalwareRustyWater

RustyWater has gathered the victim machine’s computer name.

T1082
System Information Discovery
MalwareBlackCat

BlackCat can obtain the computer name and UUID.

T1082
System Information Discovery
MalwareFysbis

Fysbis has used the command ls /etc | egrep -e"fedora\*|debian\*|gentoo\*|mandriva\*|mandrake\*|meego\*|redhat\*|lsb-\*|sun-\*|SUSE\*|release" to determine which Linux OS version is running.

T1082
System Information Discovery
MalwareIcedID

IcedID has the ability to identify the computer name and OS version on a compromised host.

T1082
System Information Discovery
MalwareVERMIN

VERMIN collects the OS name, machine name, and architecture information.

T1082
System Information Discovery
MalwareNightdoor

Nightdoor gathers information on the victim system such as CPU and Computer name as well as device drivers.

T1082
System Information Discovery
MalwareMarkiRAT

MarkiRAT can obtain the computer name from a compromised host.

T1082
System Information Discovery
MalwarePowerShower

PowerShower has collected system information on the infected host.

T1082
System Information Discovery
MalwareKazuar

Kazuar gathers information on the system.

T1082
System Information Discovery
MalwareNavRAT

NavRAT uses systeminfo on a victim’s machine.

T1082
System Information Discovery
MalwareDarkComet

DarkComet can collect the computer name, RAM used, and operating system version from the victim’s machine.

T1082
System Information Discovery
MalwarePOORAIM

POORAIM can identify system information, including battery status.

T1082
System Information Discovery
MalwareFatDuke

FatDuke can collect the user name, Windows version, computer name, and available space on discs from a compromised host.

T1082
System Information Discovery
MalwareLucifer

Lucifer can collect the computer name, system architecture, default language, and processor frequency of a compromised host.

T1082
System Information Discovery
MalwareBlackEnergy

BlackEnergy has used Systeminfo to gather the OS version, as well as information on the system configuration, BIOS, the motherboard, and the processor.

T1082
System Information Discovery
MalwarezwShell

zwShell can obtain the victim PC name and OS version.

T1082
System Information Discovery
MalwareRising Sun

Rising Sun can detect the computer name and operating system.

T1082
System Information Discovery
MalwareChrommme

Chrommme has the ability to obtain the computer name of a compromised host.

T1082
System Information Discovery
MalwareObliqueRAT

ObliqueRAT has the ability to check for blocklisted computer names on infected endpoints.

T1082
System Information Discovery
MalwareSocGholish

SocGholish has the ability to enumerate system information including the victim computer name.

T1082
System Information Discovery
MalwareSpicyOmelette

SpicyOmelette can identify the system name of a compromised host.

T1082
System Information Discovery
MalwareXAgentOSX

XAgentOSX contains the getInstalledAPP function to run ls -la /Applications to gather what applications are installed.

T1082
System Information Discovery
MalwareGreen Lambert

Green Lambert can use `uname` to identify the operating system name, version, and processor type.

T1082
System Information Discovery
MalwareLightSpy

LightSpy's second stage implant uses the `DeviceInformation` class to collect system information, including CPU usage, battery statistics, memory allocations, screen size, etc.

T1082
System Information Discovery
MalwarePUNCHBUGGY

PUNCHBUGGY can gather system information such as computer names.

T1082
System Information Discovery
MalwareKeyBoy

KeyBoy can gather extended system information, such as information about the operating system and memory.

T1082
System Information Discovery
MalwareMiniDuke

MiniDuke can gather the hostname on a compromised machine.

T1082
System Information Discovery
MalwareAnchor

Anchor can determine the hostname and linux version on a compromised host.

T1082
System Information Discovery
MalwareDarkTortilla

DarkTortilla can obtain system information by querying the `Win32_ComputerSystem`, `Win32_BIOS`, `Win32_MotherboardDevice`, `Win32_PnPEntity`, and `Win32_DiskDrive` WMI objects.

T1082
System Information Discovery
MalwareBeaverTail

BeaverTail has been known to collect basic system information. BeaverTail has also collected data to include hostname and current timestamp prior to uploading data to the API endpoint `/uploads` on the C2 server.

T1082
System Information Discovery
MalwareROKRAT

ROKRAT can gather the hostname and the OS version to ensure it doesn’t run on a Windows XP or Windows Server 2003 systems.

T1082
System Information Discovery
MalwareCORESHELL

CORESHELL collects hostname and OS version data from the victim and sends the information to its C2 server.

T1082
System Information Discovery
MalwareRunningRAT

RunningRAT gathers the OS version and processor information.

T1082
System Information Discovery
MalwareDarkWatchman

DarkWatchman can collect the OS version, system architecture, and computer name.

T1082
System Information Discovery
MalwareDyre

Dyre has the ability to identify the computer name, OS version, and hardware configuration on a compromised host.

T1082
System Information Discovery
MalwarePlugX

PlugX has collected system information including OS version, processor information, RAM size, location, host name, IP, and screen size of the infected host.

T1082
System Information Discovery
MalwareReaver

Reaver collects system information from the victim, including CPU speed, computer name, ANSI code page, OEM code page identifier for the OS, Microsoft Windows version, and memory information.

T1082
System Information Discovery
MalwareBisonal

Bisonal has used commands and API calls to gather system information.

T1082
System Information Discovery
MalwareNOOPLDR

NOOPLDR can discover the device ID and hostname from the targeted machine to use for encryption keys.

T1082
System Information Discovery
MalwareS-Type

The initial beacon packet for S-Type contains the operating system version and file system of the victim.

T1082
System Information Discovery
MalwareLumma Stealer

Lumma Stealer has gathered various system information from victim machines.

T1082
System Information Discovery
MalwareDustySky

DustySky extracts basic information about the operating system.

T1082
System Information Discovery
MalwareRemsec

Remsec can obtain the OS version information, computer name, processor architecture, machine role, and OS edition.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.