ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1082×

355 examples

TechniqueUsed byProcedure example
T1082
System Information Discovery
MalwareSolar

Solar can send basic information about the infected host to C2.

T1082
System Information Discovery
MalwarePisloader

Pisloader has a command to collect victim system information, including the system name and OS version.

T1082
System Information Discovery
MalwareGoldenSpy

GoldenSpy has gathered operating system information.

T1082
System Information Discovery
MalwareGold Dragon

Gold Dragon collects endpoint information using the systeminfo command.

T1082
System Information Discovery
MalwareAshTag

The AshTag loader and AshenOrchestrator components can collect reconnaissance data from victim machines.

T1082
System Information Discovery
MalwareCarberp

Carberp has collected the operating system version from the infected system.

T1082
System Information Discovery
MalwareNKAbuse

NKAbuse conducts multiple system checks and includes these in subsequent "heartbeat" messages to the malware's command and control server.

T1082
System Information Discovery
MalwareRevenge RAT

Revenge RAT collects the CPU information, OS information, and system language.

T1082
System Information Discovery
MalwareMacMa

MacMa can collect information about a compromised computer, including: Hardware UUID, Mac serial number, and macOS version.

T1082
System Information Discovery
MalwareMore_eggs

More_eggs has the capability to gather the OS version and computer name.

T1082
System Information Discovery
MalwareSysUpdate

SysUpdate can collect a system's architecture, operating system version, and hostname.

T1082
System Information Discovery
MalwareBackConfig

BackConfig has the ability to gather the victim's computer name.

T1082
System Information Discovery
MalwareKwampirs

Kwampirs collects OS version information such as registered owner details, manufacturer details, processor type, available storage, installed patches, hostname, version info, system date, and other system information by using the commands systeminfo, net config workstation, hostname, ver, set, and date /t.

T1082
System Information Discovery
MalwareBoomBox

BoomBox can enumerate the hostname, domain, and IP of a compromised host.

T1082
System Information Discovery
MalwareDEADEYE

DEADEYE can enumerate a victim computer's volume serial number and host name.

T1082
System Information Discovery
MalwareLAMEHUG

LAMEHUG has the ability to execute Windows commands returned from C2 to gather system information.

T1082
System Information Discovery
MalwareMango

Mango can collect the machine name of a compromised system which is later used as part of a unique victim identifier.

T1082
System Information Discovery
MalwareInnaputRAT

InnaputRAT gathers system information.

T1082
System Information Discovery
MalwareKessel

Kessel has collected the system architecture, OS version, and MAC address information.

T1082
System Information Discovery
MalwareGrimAgent

GrimAgent can collect the OS, and build version on a compromised host.

T1082
System Information Discovery
MalwareYAHOYAH

YAHOYAH checks for the system’s Windows OS version and hostname.

T1082
System Information Discovery
MalwareLokibot

Lokibot has the ability to discover the computer name and Windows product name/version.

T1082
System Information Discovery
MalwareEgregor

Egregor can perform a language check of the infected system and can query the CPU information (cupid).

T1082
System Information Discovery
MalwarePoetRAT

PoetRAT has the ability to gather information about the compromised host.

T1082
System Information Discovery
MalwareStealBit

StealBit can enumerate the computer name and domain membership of the compromised system.

T1082
System Information Discovery
MalwareFELIXROOT

FELIXROOT collects the victim’s computer name, processor architecture, OS version, and system type.

T1082
System Information Discovery
MalwareZxShell

ZxShell can collect the local hostname, operating system details, CPU speed, and total physical memory.

T1082
System Information Discovery
MalwareRIFLESPINE

RIFLESPINE can collect system information after installation on infected systems.

T1082
System Information Discovery
MalwareNDiskMonitor

NDiskMonitor obtains the victim computer name and encrypts the information to send over its C2 channel.

T1082
System Information Discovery
MalwarePenquin

Penquin can report the file system type of a compromised host to C2.

T1082
System Information Discovery
MalwareSPAWNCHIMERA

SPAWNCHIMERA has obtained system information such as release, uptime, and current time.

T1082
System Information Discovery
MalwareBabyShark

BabyShark has executed the ver command.

T1082
System Information Discovery
MalwareCannon

Cannon can gather system information from the victim’s machine such as the OS version, and machine name.

T1082
System Information Discovery
MalwareWinnti for Windows

Winnti for Windows can determine if the OS on a compromised host is newer than Windows XP.

T1082
System Information Discovery
MalwareTroll Stealer

Troll Stealer can collect local system information.

T1082
System Information Discovery
MalwareMeteor

Meteor has the ability to discover the hostname of a compromised host.

T1082
System Information Discovery
MalwarenjRAT

njRAT enumerates the victim operating system and computer name during the initial infection.

T1082
System Information Discovery
MalwareMaze

Maze has checked the language of the infected system using the "GetUSerDefaultUILanguage" function.

T1082
System Information Discovery
MalwareTURNEDUP

TURNEDUP is capable of gathering system information.

T1082
System Information Discovery
MalwareChChes

ChChes collects the victim hostname, window resolution, and Microsoft Windows version.

T1082
System Information Discovery
MalwareManjusaka

Manjusaka performs basic system profiling actions to fingerprint and register the victim system with the C2 controller.

T1082
System Information Discovery
MalwareIceApple

The IceApple Server Variable Dumper module iterates over all server variables present for the current request and returns them to the adversary.

T1082
System Information Discovery
MalwareShai-Hulud

Shai-Hulud has gathered victim system information.

T1082
System Information Discovery
MalwareJPIN

JPIN can obtain system information such as OS version and disk space.

T1082
System Information Discovery
MalwaremetaMain

metaMain can collect the computer name from a compromised host.

T1082
System Information Discovery
MalwareSideTwist

SideTwist can collect the computer name of a targeted system.

T1082
System Information Discovery
MalwareKOCTOPUS

KOCTOPUS has checked the OS version using `wmic.exe` and the `find` command.

T1082
System Information Discovery
MalwareMis-Type

The initial beacon packet for Mis-Type contains the operating system version and file system of the victim.

T1082
System Information Discovery
MalwareLunarWeb

LunarWeb can use WMI queries and shell commands such as systeminfo.exe to collect the operating system, BIOS version, and domain name of the targeted system.

T1082
System Information Discovery
MalwareXCSSET

XCSSET identifies the macOS version and uses ioreg to determine serial number.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.