ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1082×

355 examples

TechniqueUsed byProcedure example
T1082
System Information Discovery
MalwareRogueRobin

RogueRobin gathers BIOS versions and manufacturers, the number of CPU cores, the total physical memory, and the computer name.

T1082
System Information Discovery
MalwareLitePower

LitePower has the ability to enumerate the OS architecture.

T1082
System Information Discovery
MalwareStreamEx

StreamEx has the ability to enumerate system information.

T1082
System Information Discovery
MalwareSDBbot

SDBbot has the ability to identify the OS version, OS bit information and computer name.

T1082
System Information Discovery
MalwareRTM

RTM can obtain the computer name, OS version, and default language identifier.

T1082
System Information Discovery
MalwareDerusbi

Derusbi gathers the name of the local host, version of GNU Compiler Collection (GCC), and the system information about the CPU, machine, and operating system.

T1082
System Information Discovery
MalwareBlackByte Ransomware

BlackByte Ransomware gathers victim system information to generate a unique victim identifier.

T1082
System Information Discovery
MalwareSodaMaster

SodaMaster can enumerate the host name and OS version on a target system.

T1082
System Information Discovery
MalwareStrelaStealer

StrelaStealer variants collect victim system information for exfiltration.

T1082
System Information Discovery
MalwareGrandoreiro

Grandoreiro can collect the computer name and OS version from a compromised host.

T1082
System Information Discovery
MalwareLiteDuke

LiteDuke can enumerate the CPUID and BIOS version on a compromised system.

T1082
System Information Discovery
MalwareZxxZ

ZxxZ has collected the host name and operating system product name from a compromised machine.

T1082
System Information Discovery
MalwareWINDSHIELD

WINDSHIELD can gather the victim computer name.

T1082
System Information Discovery
MalwareShark

Shark can collect the GUID of a targeted machine.

T1082
System Information Discovery
MalwareBazar

Bazar can fingerprint architecture, computer name, and OS version on the compromised host. Bazar can also check if the Russian language is installed on the infected machine and terminate if it is found.

T1082
System Information Discovery
MalwareKobalos

Kobalos can record the hostname and kernel version of the target machine.

T1082
System Information Discovery
MalwareBadPatch

BadPatch collects the OS system, OS version, MAC address, and the computer name from the victim’s machine.

T1082
System Information Discovery
MalwareRATANKBA

RATANKBA gathers information about the OS architecture, OS name, and OS version/Service pack.

T1082
System Information Discovery
MalwareXLoader

XLoader can collect system information and supported language information from the victim machine.

T1082
System Information Discovery
MalwareSOUNDBITE

SOUNDBITE is capable of gathering system information.

T1082
System Information Discovery
MalwareBADCALL

BADCALL collects the computer name and host name on the compromised system.

T1082
System Information Discovery
MalwareMoonWind

MoonWind can obtain the victim hostname, Windows version, RAM amount, and screen resolution.

T1082
System Information Discovery
MalwareHiddenFace

HiddenFace can enumerate the hostname and username of the compromised system.

T1082
System Information Discovery
MalwareHermeticWiper

HermeticWiper can determine the OS version and bitness on a targeted host.

T1082
System Information Discovery
MalwareFinal1stspy

Final1stspy obtains victim Microsoft Windows version information and CPU architecture.

T1082
System Information Discovery
MalwareKapeka

Kapeka utilizes WinAPI calls and registry queries to gather system information.

T1082
System Information Discovery
MalwareLockBit 2.0

LockBit 2.0 can enumerate system information including hostname and domain information.

T1082
System Information Discovery
MalwareZebrocy

Zebrocy collects the OS version and computer name. Zebrocy also runs the systeminfo command to gather system information.

T1082
System Information Discovery
MalwareFinFisher

FinFisher checks if the victim OS is 32 or 64-bit.

T1082
System Information Discovery
MalwareSpeakUp

SpeakUp uses the cat /proc/cpuinfo | grep -c “cpu family” 2>&1 command to gather system information.

T1082
System Information Discovery
MalwareLunarMail

LunarMail can capture environmental variables on compromised hosts.

T1082
System Information Discovery
MalwareCadelspy

Cadelspy has the ability to discover information about the compromised host.

T1082
System Information Discovery
MalwareSampleCheck5000

SampleCheck5000 can create unique victim identifiers by using the compromised system’s computer name.

T1082
System Information Discovery
MalwareSUNBURST

SUNBURST collected hostname and OS version.

T1082
System Information Discovery
MalwareWingbird

Wingbird checks the victim OS version after executing to determine where to drop files based on whether the victim is 32-bit or 64-bit.

T1082
System Information Discovery
MalwareHotCroissant

HotCroissant has the ability to determine if the current user is an administrator, Windows product name, processor name, screen resolution, and physical RAM of the infected host.

T1082
System Information Discovery
MalwareServHelper

ServHelper will attempt to enumerate Windows version and system architecture.

T1082
System Information Discovery
MalwareUnknown Logger

Unknown Logger can obtain information about the victim computer name, physical memory, country, and date.

T1082
System Information Discovery
MalwareREvil

REvil can identify the username, machine name, system language, keyboard layout, and OS version on a compromised host.

T1082
System Information Discovery
MalwareValak

Valak can determine the Windows version and computer name on a compromised host.

T1082
System Information Discovery
MalwarePinchDuke

PinchDuke gathers system configuration information.

T1082
System Information Discovery
MalwareMilan

Milan can enumerate the targeted machine's name and GUID.

T1082
System Information Discovery
MalwareOSX_OCEANLOTUS.D

OSX_OCEANLOTUS.D collects processor information, memory information, computer name, hardware UUID, serial number, and operating system version. OSX_OCEANLOTUS.D has used the ioreg command to gather some of this information.

T1082
System Information Discovery
MalwareOilBooster

OilBooster can identify the compromised system's hostname which is used to create a unique identifier.

T1082
System Information Discovery
MalwareCaddyWiper

CaddyWiper can use `DsRoleGetPrimaryDomainInformation` to determine the role of the infected machine. CaddyWiper can also halt execution if the compromised host is identified as a domain controller.

T1082
System Information Discovery
MalwareCyclops Blink

Cyclops Blink has the ability to query device information.

T1082
System Information Discovery
MalwareTajMahal

TajMahal has the ability to identify hardware information, the computer name, and OS information on an infected host.

T1082
System Information Discovery
MalwareRaccoon Stealer

Raccoon Stealer gathers information on infected systems such as operating system, processor information, RAM, and display information.

T1082
System Information Discovery
MalwareCardinal RAT

Cardinal RAT can collect the hostname, Microsoft Windows version, and processor architecture from a victim machine.

T1082
System Information Discovery
MalwareBISCUIT

BISCUIT has a command to collect the processor type, operation system, computer name, and whether the system is a laptop or PC.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.