Real-world descriptions of how a group, tool or campaign used a technique.
355 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1082 System Information Discovery |
MalwareExplosive | Explosive has collected the computer name from the infected host. |
| T1082 System Information Discovery |
MalwareEpic | Epic collects the OS version, hardware information, computer name, available system memory status, and system and user language settings. |
| T1082 System Information Discovery |
MalwareLightNeuron | LightNeuron gathers the victim computer name using the Win32 API call |
| T1082 System Information Discovery |
MalwareClambling | Clambling can discover the hostname, computer name, and Windows version of a targeted machine. |
| T1082 System Information Discovery |
MalwarePureCrypter | PureCrypter can enumerate a targeted system's SerialNumber and Version. |
| T1082 System Information Discovery |
MalwareAkira | Akira uses the |
| T1082 System Information Discovery |
MalwareDarkGate | DarkGate will gather various system information such as domain, display adapter description, operating system type and version, processor type, and RAM amount. |
| T1082 System Information Discovery |
MalwareMongall | Mongall can retrieve the hostname via `gethostbyname`. |
| T1082 System Information Discovery |
MalwareNanHaiShu | NanHaiShu can gather the victim computer name and serial number. |
| T1082 System Information Discovery |
MalwareLockBit 3.0 | LockBit 3.0 can enumerate system hostname and domain. |
| T1082 System Information Discovery |
MalwareSVCReady | SVCReady has the ability to collect information such as computer name, computer manufacturer, BIOS, operating system, and firmware, including through the use of `systeminfo.exe`. |
| T1082 System Information Discovery |
MalwareHydraq | Hydraq creates a backdoor through which remote attackers can retrieve information such as computer name, OS version, processor speed, memory size, and CPU speed. |
| T1082 System Information Discovery |
MalwareSHARPSTATS | SHARPSTATS has the ability to identify the IP address, machine name, and OS of the compromised host. |
| T1082 System Information Discovery |
MalwareFerocious | Ferocious can use |
| T1082 System Information Discovery |
MalwareCaterpillar WebShell | Caterpillar WebShell has a module to gather information from the compromised asset, including the computer version, computer name, IIS version, and more. |
| T1082 System Information Discovery |
MalwareNetwalker | Netwalker can determine the system architecture it is running on to choose which version of the DLL to use. |
| T1082 System Information Discovery |
MalwareElise | Elise executes |
| T1082 System Information Discovery |
MalwareLatrodectus | Latrodectus can gather operating system information. |
| T1082 System Information Discovery |
MalwareSaint Bot | Saint Bot can identify the OS version, CPU, and other details from a victim's machine. |
| T1082 System Information Discovery |
MalwarePay2Key | Pay2Key has the ability to gather the hostname of the victim machine. |
| T1082 System Information Discovery |
MalwareChaes | Chaes has collected system information, including the machine name and OS version. |
| T1082 System Information Discovery |
MalwareLODEINFO | LODEINFO can disover machine information including OS architecture, the ANSI code page (ACP) identifier, and hostname. |
| T1082 System Information Discovery |
MalwareCharmPower | CharmPower can enumerate the OS version and computer name on a targeted system. |
| T1082 System Information Discovery |
MalwareBundlore | Bundlore will enumerate the macOS version to determine which follow-on behaviors to execute using |
| T1082 System Information Discovery |
MalwareEVILNUM | EVILNUM can obtain the computer name from the victim's system. |
| T1082 System Information Discovery |
MalwareKOMPROGO | KOMPROGO is capable of retrieving information about the infected system. |
| T1082 System Information Discovery |
MalwareSMOKEDHAM | SMOKEDHAM has used the |
| T1082 System Information Discovery |
MalwareSagerunex | Sagerunex gathers information from the infected system such as hostname. |
| T1082 System Information Discovery |
MalwareSys10 | Sys10 collects the computer name, OS versioning information, and OS install date and sends the information to the C2. |
| T1082 System Information Discovery |
MalwareRoyal | Royal can use `GetNativeSystemInfo` to enumerate system processors. |
| T1082 System Information Discovery |
MalwareGlassWorm | GlassWorm has the ability to check the OS of the victim host. GlassWorm has checked whether the OS platform value includes `darwin` prior to execution of macOS specific scripts. |
| T1082 System Information Discovery |
MalwareUroburos | Uroburos has the ability to gather basic system information and run the POSIX API `gethostbyname`. |
| T1082 System Information Discovery |
MalwareMetamorfo | Metamorfo has collected the hostname and operating system version from the compromised host. |
| T1082 System Information Discovery |
MalwareTrojan.Karagany | Trojan.Karagany can capture information regarding the victim's OS, security, and hardware configuration. |
| T1082 System Information Discovery |
MalwarePipeMon | PipeMon can collect and send OS version and computer name as a part of its C2 beacon. |
| T1082 System Information Discovery |
MalwareMagicRAT | MagicRAT collects basic system information from victim machines. |
| T1082 System Information Discovery |
MalwareKONNI | KONNI can gather the OS version, architecture information, hostname, and RAM size information from the victim’s machine and has used |
| T1082 System Information Discovery |
MalwareT9000 | T9000 gathers and beacons the operating system build number and CPU Architecture (32-bit/64-bit) during installation. |
| T1082 System Information Discovery |
Malwaregh0st RAT | gh0st RAT has gathered system architecture, processor, OS configuration, and installed hardware information. |
| T1082 System Information Discovery |
MalwareShamoon | Shamoon obtains the victim's operating system version and keyboard layout and sends the information to the C2 server. |
| T1082 System Information Discovery |
MalwareMoleNet | MoleNet can collect information about the about the system. |
| T1082 System Information Discovery |
MalwareBLUELIGHT | BLUELIGHT has collected the computer name and OS version from victim machines. |
| T1082 System Information Discovery |
MalwareIxeshe | Ixeshe collects the computer name of the victim's system during the initial infection. |
| T1082 System Information Discovery |
MalwareMicropsia | Micropsia gathers the hostname and OS version from the victim’s machine. |
| T1082 System Information Discovery |
MalwareKerrdown | Kerrdown has the ability to determine if the compromised host is running a 32 or 64 bit OS architecture. |
| T1082 System Information Discovery |
MalwareRedLine Stealer | RedLine Stealer can collect information about the local system. |
| T1082 System Information Discovery |
MalwareBlack Basta | Black Basta can collect system boot configuration and CPU information. |
| T1082 System Information Discovery |
MalwareStoneDrill | StoneDrill has the capability to discover the system OS, Windows version, architecture and environment. |
| T1082 System Information Discovery |
MalwareOopsIE | OopsIE checks for information on the CPU fan, temperature, mouse, hard disk, and motherboard as part of its anti-VM checks. |
| T1082 System Information Discovery |
Malware4H RAT | 4H RAT sends an OS version identifier in its beacons. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.