Real-world descriptions of how a group, tool or campaign used a technique.
355 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1082 System Information Discovery |
MalwareOkrum | Okrum can collect computer name, locale information, and information about the OS and architecture. |
| T1082 System Information Discovery |
MalwareBonadan | Bonadan has discovered the OS version, CPU model, and RAM size of the system it has been installed on. |
| T1082 System Information Discovery |
MalwareLine Dancer | Line Dancer can gather system configuration information by running the native `show configuration` command. |
| T1082 System Information Discovery |
MalwareNeoichor | Neoichor can collect the OS version and computer name from a compromised host. |
| T1082 System Information Discovery |
MalwareRaspberry Robin | Raspberry Robin performs several system checks as part of anti-analysis mechanisms, including querying the operating system build number, processor vendor and type, video controller, and CPU temperature. |
| T1082 System Information Discovery |
MalwareMispadu | Mispadu collects the OS version, computer name, and language ID. |
| T1082 System Information Discovery |
MalwareDiavol | Diavol can collect the computer name and OS version from the system. |
| T1082 System Information Discovery |
MalwareRustyWater | RustyWater has gathered the victim machine’s computer name. |
| T1082 System Information Discovery |
MalwareBlackCat | BlackCat can obtain the computer name and UUID. |
| T1082 System Information Discovery |
MalwareFysbis | Fysbis has used the command |
| T1082 System Information Discovery |
MalwareIcedID | IcedID has the ability to identify the computer name and OS version on a compromised host. |
| T1082 System Information Discovery |
MalwareVERMIN | VERMIN collects the OS name, machine name, and architecture information. |
| T1082 System Information Discovery |
MalwareNightdoor | Nightdoor gathers information on the victim system such as CPU and Computer name as well as device drivers. |
| T1082 System Information Discovery |
MalwareMarkiRAT | MarkiRAT can obtain the computer name from a compromised host. |
| T1082 System Information Discovery |
MalwarePowerShower | PowerShower has collected system information on the infected host. |
| T1082 System Information Discovery |
MalwareKazuar | Kazuar gathers information on the system. |
| T1082 System Information Discovery |
MalwareNavRAT | NavRAT uses |
| T1082 System Information Discovery |
MalwareDarkComet | DarkComet can collect the computer name, RAM used, and operating system version from the victim’s machine. |
| T1082 System Information Discovery |
MalwarePOORAIM | POORAIM can identify system information, including battery status. |
| T1082 System Information Discovery |
MalwareFatDuke | FatDuke can collect the user name, Windows version, computer name, and available space on discs from a compromised host. |
| T1082 System Information Discovery |
MalwareLucifer | Lucifer can collect the computer name, system architecture, default language, and processor frequency of a compromised host. |
| T1082 System Information Discovery |
MalwareBlackEnergy | BlackEnergy has used Systeminfo to gather the OS version, as well as information on the system configuration, BIOS, the motherboard, and the processor. |
| T1082 System Information Discovery |
MalwarezwShell | zwShell can obtain the victim PC name and OS version. |
| T1082 System Information Discovery |
MalwareRising Sun | Rising Sun can detect the computer name and operating system. |
| T1082 System Information Discovery |
MalwareChrommme | Chrommme has the ability to obtain the computer name of a compromised host. |
| T1082 System Information Discovery |
MalwareObliqueRAT | ObliqueRAT has the ability to check for blocklisted computer names on infected endpoints. |
| T1082 System Information Discovery |
MalwareSocGholish | SocGholish has the ability to enumerate system information including the victim computer name. |
| T1082 System Information Discovery |
MalwareSpicyOmelette | SpicyOmelette can identify the system name of a compromised host. |
| T1082 System Information Discovery |
MalwareXAgentOSX | XAgentOSX contains the getInstalledAPP function to run |
| T1082 System Information Discovery |
MalwareGreen Lambert | Green Lambert can use `uname` to identify the operating system name, version, and processor type. |
| T1082 System Information Discovery |
MalwareLightSpy | LightSpy's second stage implant uses the `DeviceInformation` class to collect system information, including CPU usage, battery statistics, memory allocations, screen size, etc. |
| T1082 System Information Discovery |
MalwarePUNCHBUGGY | PUNCHBUGGY can gather system information such as computer names. |
| T1082 System Information Discovery |
MalwareKeyBoy | KeyBoy can gather extended system information, such as information about the operating system and memory. |
| T1082 System Information Discovery |
MalwareMiniDuke | MiniDuke can gather the hostname on a compromised machine. |
| T1082 System Information Discovery |
MalwareAnchor | Anchor can determine the hostname and linux version on a compromised host. |
| T1082 System Information Discovery |
MalwareDarkTortilla | DarkTortilla can obtain system information by querying the `Win32_ComputerSystem`, `Win32_BIOS`, `Win32_MotherboardDevice`, `Win32_PnPEntity`, and `Win32_DiskDrive` WMI objects. |
| T1082 System Information Discovery |
MalwareBeaverTail | BeaverTail has been known to collect basic system information. BeaverTail has also collected data to include hostname and current timestamp prior to uploading data to the API endpoint `/uploads` on the C2 server. |
| T1082 System Information Discovery |
MalwareROKRAT | ROKRAT can gather the hostname and the OS version to ensure it doesn’t run on a Windows XP or Windows Server 2003 systems. |
| T1082 System Information Discovery |
MalwareCORESHELL | CORESHELL collects hostname and OS version data from the victim and sends the information to its C2 server. |
| T1082 System Information Discovery |
MalwareRunningRAT | RunningRAT gathers the OS version and processor information. |
| T1082 System Information Discovery |
MalwareDarkWatchman | DarkWatchman can collect the OS version, system architecture, and computer name. |
| T1082 System Information Discovery |
MalwareDyre | Dyre has the ability to identify the computer name, OS version, and hardware configuration on a compromised host. |
| T1082 System Information Discovery |
MalwarePlugX | PlugX has collected system information including OS version, processor information, RAM size, location, host name, IP, and screen size of the infected host. |
| T1082 System Information Discovery |
MalwareReaver | Reaver collects system information from the victim, including CPU speed, computer name, ANSI code page, OEM code page identifier for the OS, Microsoft Windows version, and memory information. |
| T1082 System Information Discovery |
MalwareBisonal | Bisonal has used commands and API calls to gather system information. |
| T1082 System Information Discovery |
MalwareNOOPLDR | NOOPLDR can discover the device ID and hostname from the targeted machine to use for encryption keys. |
| T1082 System Information Discovery |
MalwareS-Type | The initial beacon packet for S-Type contains the operating system version and file system of the victim. |
| T1082 System Information Discovery |
MalwareLumma Stealer | Lumma Stealer has gathered various system information from victim machines. |
| T1082 System Information Discovery |
MalwareDustySky | DustySky extracts basic information about the operating system. |
| T1082 System Information Discovery |
MalwareRemsec | Remsec can obtain the OS version information, computer name, processor architecture, machine role, and OS edition. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.