Real-world descriptions of how a group, tool or campaign used a technique.
355 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1082 System Information Discovery |
MalwareSolar | Solar can send basic information about the infected host to C2. |
| T1082 System Information Discovery |
MalwarePisloader | Pisloader has a command to collect victim system information, including the system name and OS version. |
| T1082 System Information Discovery |
MalwareGoldenSpy | GoldenSpy has gathered operating system information. |
| T1082 System Information Discovery |
MalwareGold Dragon | Gold Dragon collects endpoint information using the |
| T1082 System Information Discovery |
MalwareAshTag | The AshTag loader and AshenOrchestrator components can collect reconnaissance data from victim machines. |
| T1082 System Information Discovery |
MalwareCarberp | Carberp has collected the operating system version from the infected system. |
| T1082 System Information Discovery |
MalwareNKAbuse | NKAbuse conducts multiple system checks and includes these in subsequent "heartbeat" messages to the malware's command and control server. |
| T1082 System Information Discovery |
MalwareRevenge RAT | Revenge RAT collects the CPU information, OS information, and system language. |
| T1082 System Information Discovery |
MalwareMacMa | MacMa can collect information about a compromised computer, including: Hardware UUID, Mac serial number, and macOS version. |
| T1082 System Information Discovery |
MalwareMore_eggs | More_eggs has the capability to gather the OS version and computer name. |
| T1082 System Information Discovery |
MalwareSysUpdate | SysUpdate can collect a system's architecture, operating system version, and hostname. |
| T1082 System Information Discovery |
MalwareBackConfig | BackConfig has the ability to gather the victim's computer name. |
| T1082 System Information Discovery |
MalwareKwampirs | Kwampirs collects OS version information such as registered owner details, manufacturer details, processor type, available storage, installed patches, hostname, version info, system date, and other system information by using the commands |
| T1082 System Information Discovery |
MalwareBoomBox | BoomBox can enumerate the hostname, domain, and IP of a compromised host. |
| T1082 System Information Discovery |
MalwareDEADEYE | DEADEYE can enumerate a victim computer's volume serial number and host name. |
| T1082 System Information Discovery |
MalwareLAMEHUG | LAMEHUG has the ability to execute Windows commands returned from C2 to gather system information. |
| T1082 System Information Discovery |
MalwareMango | Mango can collect the machine name of a compromised system which is later used as part of a unique victim identifier. |
| T1082 System Information Discovery |
MalwareInnaputRAT | InnaputRAT gathers system information. |
| T1082 System Information Discovery |
MalwareKessel | Kessel has collected the system architecture, OS version, and MAC address information. |
| T1082 System Information Discovery |
MalwareGrimAgent | GrimAgent can collect the OS, and build version on a compromised host. |
| T1082 System Information Discovery |
MalwareYAHOYAH | YAHOYAH checks for the system’s Windows OS version and hostname. |
| T1082 System Information Discovery |
MalwareLokibot | Lokibot has the ability to discover the computer name and Windows product name/version. |
| T1082 System Information Discovery |
MalwareEgregor | Egregor can perform a language check of the infected system and can query the CPU information (cupid). |
| T1082 System Information Discovery |
MalwarePoetRAT | PoetRAT has the ability to gather information about the compromised host. |
| T1082 System Information Discovery |
MalwareStealBit | StealBit can enumerate the computer name and domain membership of the compromised system. |
| T1082 System Information Discovery |
MalwareFELIXROOT | FELIXROOT collects the victim’s computer name, processor architecture, OS version, and system type. |
| T1082 System Information Discovery |
MalwareZxShell | ZxShell can collect the local hostname, operating system details, CPU speed, and total physical memory. |
| T1082 System Information Discovery |
MalwareRIFLESPINE | RIFLESPINE can collect system information after installation on infected systems. |
| T1082 System Information Discovery |
MalwareNDiskMonitor | NDiskMonitor obtains the victim computer name and encrypts the information to send over its C2 channel. |
| T1082 System Information Discovery |
MalwarePenquin | Penquin can report the file system type of a compromised host to C2. |
| T1082 System Information Discovery |
MalwareSPAWNCHIMERA | SPAWNCHIMERA has obtained system information such as release, uptime, and current time. |
| T1082 System Information Discovery |
MalwareBabyShark | BabyShark has executed the |
| T1082 System Information Discovery |
MalwareCannon | Cannon can gather system information from the victim’s machine such as the OS version, and machine name. |
| T1082 System Information Discovery |
MalwareWinnti for Windows | Winnti for Windows can determine if the OS on a compromised host is newer than Windows XP. |
| T1082 System Information Discovery |
MalwareTroll Stealer | Troll Stealer can collect local system information. |
| T1082 System Information Discovery |
MalwareMeteor | Meteor has the ability to discover the hostname of a compromised host. |
| T1082 System Information Discovery |
MalwarenjRAT | njRAT enumerates the victim operating system and computer name during the initial infection. |
| T1082 System Information Discovery |
MalwareMaze | Maze has checked the language of the infected system using the "GetUSerDefaultUILanguage" function. |
| T1082 System Information Discovery |
MalwareTURNEDUP | TURNEDUP is capable of gathering system information. |
| T1082 System Information Discovery |
MalwareChChes | ChChes collects the victim hostname, window resolution, and Microsoft Windows version. |
| T1082 System Information Discovery |
MalwareManjusaka | Manjusaka performs basic system profiling actions to fingerprint and register the victim system with the C2 controller. |
| T1082 System Information Discovery |
MalwareIceApple | The IceApple Server Variable Dumper module iterates over all server variables present for the current request and returns them to the adversary. |
| T1082 System Information Discovery |
MalwareShai-Hulud | Shai-Hulud has gathered victim system information. |
| T1082 System Information Discovery |
MalwareJPIN | JPIN can obtain system information such as OS version and disk space. |
| T1082 System Information Discovery |
MalwaremetaMain | metaMain can collect the computer name from a compromised host. |
| T1082 System Information Discovery |
MalwareSideTwist | SideTwist can collect the computer name of a targeted system. |
| T1082 System Information Discovery |
MalwareKOCTOPUS | KOCTOPUS has checked the OS version using `wmic.exe` and the `find` command. |
| T1082 System Information Discovery |
MalwareMis-Type | The initial beacon packet for Mis-Type contains the operating system version and file system of the victim. |
| T1082 System Information Discovery |
MalwareLunarWeb | LunarWeb can use WMI queries and shell commands such as systeminfo.exe to collect the operating system, BIOS version, and domain name of the targeted system. |
| T1082 System Information Discovery |
MalwareXCSSET | XCSSET identifies the macOS version and uses |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.