ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1082×

355 examples

TechniqueUsed byProcedure example
T1082
System Information Discovery
MalwareOctopus

Octopus can collect the computer name, OS version, and OS architecture information.

T1082
System Information Discovery
MalwareQilin

Qilin can detect whether a system is running FreeBSD, VMkernel (ESXi), Nutanix AHV, or a standard Linux distribution to enable platform-specific encryption behaviors.

T1082
System Information Discovery
MalwareAppleJeus

AppleJeus has collected the victim host information after infection.

T1082
System Information Discovery
MalwareSoreFang

SoreFang can collect the hostname, operating system configuration, and product ID on victim machines by executing Systeminfo.

T1082
System Information Discovery
MalwareSTARWHALE

STARWHALE can gather the computer name of an infected host.

T1082
System Information Discovery
MalwareMirageFox

MirageFox can collect CPU and architecture information from the victim’s machine.

T1082
System Information Discovery
MalwareIndustroyer

Industroyer collects the victim machine’s Windows GUID.

T1082
System Information Discovery
MalwareLazyWiper

LazyWiper has used `[System.Net.Dns]::GetHostName()` and `$env:COMPUTERNAME` to enumerate the hostname of a system and determine if it is a domain controller.

T1082
System Information Discovery
MalwareDownPaper

DownPaper collects the victim host name and serial number, and then sends the information to the C2 server.

T1082
System Information Discovery
MalwareCozyCar

A system info module in CozyCar gathers information on the victim host’s configuration.

T1082
System Information Discovery
MalwareKevin

Kevin can enumerate the OS version and hostname of a targeted machine.

T1082
System Information Discovery
MalwareAgent Tesla

Agent Tesla can collect the system's computer name and also has the capability to collect information on the processor, memory, OS, and video card from the system.

T1082
System Information Discovery
MalwarePasam

Pasam creates a backdoor through which remote attackers can retrieve information like hostname.

T1082
System Information Discovery
MalwarePOWERSTATS

POWERSTATS can retrieve OS name/architecture and computer/domain name information from compromised hosts.

T1082
System Information Discovery
MalwareLinfo

Linfo creates a backdoor through which remote attackers can retrieve system information.

T1082
System Information Discovery
MalwareShadowPad

ShadowPad has discovered system information including memory status, CPU frequency, and OS versions.

T1082
System Information Discovery
MalwareAstaroth

Astaroth collects the machine name and keyboard language from the system.

T1082
System Information Discovery
MalwareQakBot

QakBot can collect system information including the OS version and domain on a compromised host.

T1082
System Information Discovery
MalwareSYSCON

SYSCON has the ability to use Systeminfo to identify system information.

T1082
System Information Discovery
MalwareGelsemium

Gelsemium can determine the operating system and whether a targeted machine has a 32 or 64 bit architecture.

T1082
System Information Discovery
MalwarejRAT

jRAT collects information about the OS (version, build type, install date) as well as system up-time upon receiving a connection from a backdoor.

T1082
System Information Discovery
MalwareDridex

Dridex has collected the computer name and OS architecture information from the system.

T1082
System Information Discovery
MalwareOSX/Shlayer

OSX/Shlayer has collected the IOPlatformUUID, session UID, and the OS version using the command sw_vers -productVersion.

T1082
System Information Discovery
MalwareDenis

Denis collects OS information and the computer name from the victim’s machine.

T1082
System Information Discovery
MalwareSplatCloak

SplatCloak has collected the Windows build number using the windows kernel API `RtlGetVersion` to determine if the response is 19000 or higher (Windows 10 version 2004 or later).

T1082
System Information Discovery
MalwareComnie

Comnie collects the hostname of the victim machine.

T1082
System Information Discovery
MalwareOSInfo

OSInfo discovers information about the infected machine.

T1082
System Information Discovery
MalwareLizar

Lizar can collect the computer name from the machine.

T1082
System Information Discovery
MalwareDtrack

Dtrack can collect the victim's computer name, hostname and adapter information to create a unique identifier.

T1082
System Information Discovery
MalwareLoudMiner

LoudMiner has monitored CPU usage.

T1082
System Information Discovery
MalwareAzorult

Azorult can collect the machine information, system architecture, the OS version, computer name, Windows product name, the number of CPU cores, video card information, and the system language.

T1082
System Information Discovery
MalwareBACKSPACE

During its initial execution, BACKSPACE extracts operating system information from the infected host.

T1082
System Information Discovery
MalwareUPPERCUT

UPPERCUT has the capability to gather the system’s hostname and OS version.

T1082
System Information Discovery
MalwareADVSTORESHELL

ADVSTORESHELL can run Systeminfo to gather information about the victim.

T1082
System Information Discovery
MalwareStrifeWater

StrifeWater can collect the OS version, architecture, and machine name to create a unique token for the infected host.

T1082
System Information Discovery
MalwareWarzoneRAT

WarzoneRAT can collect compromised host information, including OS version, PC name, RAM size, and CPU details.

T1082
System Information Discovery
MalwareSLOTHFULMEDIA

SLOTHFULMEDIA has collected system name, OS version, adapter information, and memory usage from a victim machine.

T1082
System Information Discovery
MalwareFALLCHILL

FALLCHILL can collect operating system (OS) version information, processor information, and system name from the victim.

T1082
System Information Discovery
MalwareXORIndex Loader

XORIndex Loader has the ability to collect the hostname, OS Username, Geolocation, and OS version of an infected host.

T1082
System Information Discovery
ToolCovenant

Covenant implants can gather basic information on infected systems.

T1082
System Information Discovery
ToolDiskpart

Diskpart can show information about the selected disk, partition, volume, or virtual hard disk (VHD).

T1082
System Information Discovery
ToolShimRatReporter

ShimRatReporter gathered the operating system name and specific Windows version of an infected machine.

T1082
System Information Discovery
ToolSILENTTRINITY

SILENTTRINITY can collect information related to a compromised host, including OS version.

T1082
System Information Discovery
ToolEmpire

Empire can enumerate host system information like OS, architecture, domain name, applied patches, and more.

T1082
System Information Discovery
Tooldsquery

dsquery has the ability to enumerate various information, such as the operating system and host name, for systems within a domain.

T1082
System Information Discovery
ToolPoshC2

PoshC2 contains modules, such as Get-ComputerInfo, for enumerating common system information.

T1082
System Information Discovery
ToolRemcos

Remcos can collect the OS version and process architecture of compromised hosts.

T1082
System Information Discovery
ToolSysteminfo

Systeminfo can be used to gather information about the operating system.

T1082
System Information Discovery
Toolcmd

cmd can be used to find information about the operating system.

T1082
System Information Discovery
ToolKoadic

Koadic can obtain the OS version and build, computer name, and processor architecture from a compromised host.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.