ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1082×

355 examples

TechniqueUsed byProcedure example
T1082
System Information Discovery
MalwareExplosive

Explosive has collected the computer name from the infected host.

T1082
System Information Discovery
MalwareEpic

Epic collects the OS version, hardware information, computer name, available system memory status, and system and user language settings.

T1082
System Information Discovery
MalwareLightNeuron

LightNeuron gathers the victim computer name using the Win32 API call GetComputerName.

T1082
System Information Discovery
MalwareClambling

Clambling can discover the hostname, computer name, and Windows version of a targeted machine.

T1082
System Information Discovery
MalwarePureCrypter

PureCrypter can enumerate a targeted system's SerialNumber and Version.

T1082
System Information Discovery
MalwareAkira

Akira uses the GetSystemInfo Windows function to determine the number of processors on a victim machine.

T1082
System Information Discovery
MalwareDarkGate

DarkGate will gather various system information such as domain, display adapter description, operating system type and version, processor type, and RAM amount.

T1082
System Information Discovery
MalwareMongall

Mongall can retrieve the hostname via `gethostbyname`.

T1082
System Information Discovery
MalwareNanHaiShu

NanHaiShu can gather the victim computer name and serial number.

T1082
System Information Discovery
MalwareLockBit 3.0

LockBit 3.0 can enumerate system hostname and domain.

T1082
System Information Discovery
MalwareSVCReady

SVCReady has the ability to collect information such as computer name, computer manufacturer, BIOS, operating system, and firmware, including through the use of `systeminfo.exe`.

T1082
System Information Discovery
MalwareHydraq

Hydraq creates a backdoor through which remote attackers can retrieve information such as computer name, OS version, processor speed, memory size, and CPU speed.

T1082
System Information Discovery
MalwareSHARPSTATS

SHARPSTATS has the ability to identify the IP address, machine name, and OS of the compromised host.

T1082
System Information Discovery
MalwareFerocious

Ferocious can use GET.WORKSPACE in Microsoft Excel to determine the OS version of the compromised host.

T1082
System Information Discovery
MalwareCaterpillar WebShell

Caterpillar WebShell has a module to gather information from the compromised asset, including the computer version, computer name, IIS version, and more.

T1082
System Information Discovery
MalwareNetwalker

Netwalker can determine the system architecture it is running on to choose which version of the DLL to use.

T1082
System Information Discovery
MalwareElise

Elise executes systeminfo after initial communication is made to the remote server.

T1082
System Information Discovery
MalwareLatrodectus

Latrodectus can gather operating system information.

T1082
System Information Discovery
MalwareSaint Bot

Saint Bot can identify the OS version, CPU, and other details from a victim's machine.

T1082
System Information Discovery
MalwarePay2Key

Pay2Key has the ability to gather the hostname of the victim machine.

T1082
System Information Discovery
MalwareChaes

Chaes has collected system information, including the machine name and OS version.

T1082
System Information Discovery
MalwareLODEINFO

LODEINFO can disover machine information including OS architecture, the ANSI code page (ACP) identifier, and hostname.

T1082
System Information Discovery
MalwareCharmPower

CharmPower can enumerate the OS version and computer name on a targeted system.

T1082
System Information Discovery
MalwareBundlore

Bundlore will enumerate the macOS version to determine which follow-on behaviors to execute using /usr/bin/sw_vers -productVersion.

T1082
System Information Discovery
MalwareEVILNUM

EVILNUM can obtain the computer name from the victim's system.

T1082
System Information Discovery
MalwareKOMPROGO

KOMPROGO is capable of retrieving information about the infected system.

T1082
System Information Discovery
MalwareSMOKEDHAM

SMOKEDHAM has used the systeminfo command on a compromised host.

T1082
System Information Discovery
MalwareSagerunex

Sagerunex gathers information from the infected system such as hostname.

T1082
System Information Discovery
MalwareSys10

Sys10 collects the computer name, OS versioning information, and OS install date and sends the information to the C2.

T1082
System Information Discovery
MalwareRoyal

Royal can use `GetNativeSystemInfo` to enumerate system processors.

T1082
System Information Discovery
MalwareGlassWorm

GlassWorm has the ability to check the OS of the victim host. GlassWorm has checked whether the OS platform value includes `darwin` prior to execution of macOS specific scripts.

T1082
System Information Discovery
MalwareUroburos

Uroburos has the ability to gather basic system information and run the POSIX API `gethostbyname`.

T1082
System Information Discovery
MalwareMetamorfo

Metamorfo has collected the hostname and operating system version from the compromised host.

T1082
System Information Discovery
MalwareTrojan.Karagany

Trojan.Karagany can capture information regarding the victim's OS, security, and hardware configuration.

T1082
System Information Discovery
MalwarePipeMon

PipeMon can collect and send OS version and computer name as a part of its C2 beacon.

T1082
System Information Discovery
MalwareMagicRAT

MagicRAT collects basic system information from victim machines.

T1082
System Information Discovery
MalwareKONNI

KONNI can gather the OS version, architecture information, hostname, and RAM size information from the victim’s machine and has used cmd /c systeminfo command to get a snapshot of the current system state of the target machine.

T1082
System Information Discovery
MalwareT9000

T9000 gathers and beacons the operating system build number and CPU Architecture (32-bit/64-bit) during installation.

T1082
System Information Discovery
Malwaregh0st RAT

gh0st RAT has gathered system architecture, processor, OS configuration, and installed hardware information.

T1082
System Information Discovery
MalwareShamoon

Shamoon obtains the victim's operating system version and keyboard layout and sends the information to the C2 server.

T1082
System Information Discovery
MalwareMoleNet

MoleNet can collect information about the about the system.

T1082
System Information Discovery
MalwareBLUELIGHT

BLUELIGHT has collected the computer name and OS version from victim machines.

T1082
System Information Discovery
MalwareIxeshe

Ixeshe collects the computer name of the victim's system during the initial infection.

T1082
System Information Discovery
MalwareMicropsia

Micropsia gathers the hostname and OS version from the victim’s machine.

T1082
System Information Discovery
MalwareKerrdown

Kerrdown has the ability to determine if the compromised host is running a 32 or 64 bit OS architecture.

T1082
System Information Discovery
MalwareRedLine Stealer

RedLine Stealer can collect information about the local system.

T1082
System Information Discovery
MalwareBlack Basta

Black Basta can collect system boot configuration and CPU information.

T1082
System Information Discovery
MalwareStoneDrill

StoneDrill has the capability to discover the system OS, Windows version, architecture and environment.

T1082
System Information Discovery
MalwareOopsIE

OopsIE checks for information on the CPU fan, temperature, mouse, hard disk, and motherboard as part of its anti-VM checks.

T1082
System Information Discovery
Malware4H RAT

4H RAT sends an OS version identifier in its beacons.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.