Real-world descriptions of how a group, tool or campaign used a technique.
355 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1082 System Information Discovery |
MalwareRogueRobin | RogueRobin gathers BIOS versions and manufacturers, the number of CPU cores, the total physical memory, and the computer name. |
| T1082 System Information Discovery |
MalwareLitePower | LitePower has the ability to enumerate the OS architecture. |
| T1082 System Information Discovery |
MalwareStreamEx | StreamEx has the ability to enumerate system information. |
| T1082 System Information Discovery |
MalwareSDBbot | SDBbot has the ability to identify the OS version, OS bit information and computer name. |
| T1082 System Information Discovery |
MalwareRTM | RTM can obtain the computer name, OS version, and default language identifier. |
| T1082 System Information Discovery |
MalwareDerusbi | Derusbi gathers the name of the local host, version of GNU Compiler Collection (GCC), and the system information about the CPU, machine, and operating system. |
| T1082 System Information Discovery |
MalwareBlackByte Ransomware | BlackByte Ransomware gathers victim system information to generate a unique victim identifier. |
| T1082 System Information Discovery |
MalwareSodaMaster | SodaMaster can enumerate the host name and OS version on a target system. |
| T1082 System Information Discovery |
MalwareStrelaStealer | StrelaStealer variants collect victim system information for exfiltration. |
| T1082 System Information Discovery |
MalwareGrandoreiro | Grandoreiro can collect the computer name and OS version from a compromised host. |
| T1082 System Information Discovery |
MalwareLiteDuke | LiteDuke can enumerate the CPUID and BIOS version on a compromised system. |
| T1082 System Information Discovery |
MalwareZxxZ | ZxxZ has collected the host name and operating system product name from a compromised machine. |
| T1082 System Information Discovery |
MalwareWINDSHIELD | WINDSHIELD can gather the victim computer name. |
| T1082 System Information Discovery |
MalwareShark | Shark can collect the GUID of a targeted machine. |
| T1082 System Information Discovery |
MalwareBazar | Bazar can fingerprint architecture, computer name, and OS version on the compromised host. Bazar can also check if the Russian language is installed on the infected machine and terminate if it is found. |
| T1082 System Information Discovery |
MalwareKobalos | Kobalos can record the hostname and kernel version of the target machine. |
| T1082 System Information Discovery |
MalwareBadPatch | BadPatch collects the OS system, OS version, MAC address, and the computer name from the victim’s machine. |
| T1082 System Information Discovery |
MalwareRATANKBA | RATANKBA gathers information about the OS architecture, OS name, and OS version/Service pack. |
| T1082 System Information Discovery |
MalwareXLoader | XLoader can collect system information and supported language information from the victim machine. |
| T1082 System Information Discovery |
MalwareSOUNDBITE | SOUNDBITE is capable of gathering system information. |
| T1082 System Information Discovery |
MalwareBADCALL | BADCALL collects the computer name and host name on the compromised system. |
| T1082 System Information Discovery |
MalwareMoonWind | MoonWind can obtain the victim hostname, Windows version, RAM amount, and screen resolution. |
| T1082 System Information Discovery |
MalwareHiddenFace | HiddenFace can enumerate the hostname and username of the compromised system. |
| T1082 System Information Discovery |
MalwareHermeticWiper | HermeticWiper can determine the OS version and bitness on a targeted host. |
| T1082 System Information Discovery |
MalwareFinal1stspy | Final1stspy obtains victim Microsoft Windows version information and CPU architecture. |
| T1082 System Information Discovery |
MalwareKapeka | Kapeka utilizes WinAPI calls and registry queries to gather system information. |
| T1082 System Information Discovery |
MalwareLockBit 2.0 | LockBit 2.0 can enumerate system information including hostname and domain information. |
| T1082 System Information Discovery |
MalwareZebrocy | Zebrocy collects the OS version and computer name. Zebrocy also runs the |
| T1082 System Information Discovery |
MalwareFinFisher | FinFisher checks if the victim OS is 32 or 64-bit. |
| T1082 System Information Discovery |
MalwareSpeakUp | SpeakUp uses the |
| T1082 System Information Discovery |
MalwareLunarMail | LunarMail can capture environmental variables on compromised hosts. |
| T1082 System Information Discovery |
MalwareCadelspy | Cadelspy has the ability to discover information about the compromised host. |
| T1082 System Information Discovery |
MalwareSampleCheck5000 | SampleCheck5000 can create unique victim identifiers by using the compromised system’s computer name. |
| T1082 System Information Discovery |
MalwareSUNBURST | SUNBURST collected hostname and OS version. |
| T1082 System Information Discovery |
MalwareWingbird | Wingbird checks the victim OS version after executing to determine where to drop files based on whether the victim is 32-bit or 64-bit. |
| T1082 System Information Discovery |
MalwareHotCroissant | HotCroissant has the ability to determine if the current user is an administrator, Windows product name, processor name, screen resolution, and physical RAM of the infected host. |
| T1082 System Information Discovery |
MalwareServHelper | ServHelper will attempt to enumerate Windows version and system architecture. |
| T1082 System Information Discovery |
MalwareUnknown Logger | Unknown Logger can obtain information about the victim computer name, physical memory, country, and date. |
| T1082 System Information Discovery |
MalwareREvil | REvil can identify the username, machine name, system language, keyboard layout, and OS version on a compromised host. |
| T1082 System Information Discovery |
MalwareValak | Valak can determine the Windows version and computer name on a compromised host. |
| T1082 System Information Discovery |
MalwarePinchDuke | PinchDuke gathers system configuration information. |
| T1082 System Information Discovery |
MalwareMilan | Milan can enumerate the targeted machine's name and GUID. |
| T1082 System Information Discovery |
MalwareOSX_OCEANLOTUS.D | OSX_OCEANLOTUS.D collects processor information, memory information, computer name, hardware UUID, serial number, and operating system version. OSX_OCEANLOTUS.D has used the |
| T1082 System Information Discovery |
MalwareOilBooster | OilBooster can identify the compromised system's hostname which is used to create a unique identifier. |
| T1082 System Information Discovery |
MalwareCaddyWiper | CaddyWiper can use `DsRoleGetPrimaryDomainInformation` to determine the role of the infected machine. CaddyWiper can also halt execution if the compromised host is identified as a domain controller. |
| T1082 System Information Discovery |
MalwareCyclops Blink | Cyclops Blink has the ability to query device information. |
| T1082 System Information Discovery |
MalwareTajMahal | TajMahal has the ability to identify hardware information, the computer name, and OS information on an infected host. |
| T1082 System Information Discovery |
MalwareRaccoon Stealer | Raccoon Stealer gathers information on infected systems such as operating system, processor information, RAM, and display information. |
| T1082 System Information Discovery |
MalwareCardinal RAT | Cardinal RAT can collect the hostname, Microsoft Windows version, and processor architecture from a victim machine. |
| T1082 System Information Discovery |
MalwareBISCUIT | BISCUIT has a command to collect the processor type, operation system, computer name, and whether the system is a laptop or PC. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.