Real-world descriptions of how a group, tool or campaign used a technique.
355 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1082 System Information Discovery |
MalwareOctopus | Octopus can collect the computer name, OS version, and OS architecture information. |
| T1082 System Information Discovery |
MalwareQilin | Qilin can detect whether a system is running FreeBSD, VMkernel (ESXi), Nutanix AHV, or a standard Linux distribution to enable platform-specific encryption behaviors. |
| T1082 System Information Discovery |
MalwareAppleJeus | AppleJeus has collected the victim host information after infection. |
| T1082 System Information Discovery |
MalwareSoreFang | SoreFang can collect the hostname, operating system configuration, and product ID on victim machines by executing Systeminfo. |
| T1082 System Information Discovery |
MalwareSTARWHALE | STARWHALE can gather the computer name of an infected host. |
| T1082 System Information Discovery |
MalwareMirageFox | MirageFox can collect CPU and architecture information from the victim’s machine. |
| T1082 System Information Discovery |
MalwareIndustroyer | Industroyer collects the victim machine’s Windows GUID. |
| T1082 System Information Discovery |
MalwareLazyWiper | LazyWiper has used `[System.Net.Dns]::GetHostName()` and `$env:COMPUTERNAME` to enumerate the hostname of a system and determine if it is a domain controller. |
| T1082 System Information Discovery |
MalwareDownPaper | DownPaper collects the victim host name and serial number, and then sends the information to the C2 server. |
| T1082 System Information Discovery |
MalwareCozyCar | A system info module in CozyCar gathers information on the victim host’s configuration. |
| T1082 System Information Discovery |
MalwareKevin | Kevin can enumerate the OS version and hostname of a targeted machine. |
| T1082 System Information Discovery |
MalwareAgent Tesla | Agent Tesla can collect the system's computer name and also has the capability to collect information on the processor, memory, OS, and video card from the system. |
| T1082 System Information Discovery |
MalwarePasam | Pasam creates a backdoor through which remote attackers can retrieve information like hostname. |
| T1082 System Information Discovery |
MalwarePOWERSTATS | POWERSTATS can retrieve OS name/architecture and computer/domain name information from compromised hosts. |
| T1082 System Information Discovery |
MalwareLinfo | Linfo creates a backdoor through which remote attackers can retrieve system information. |
| T1082 System Information Discovery |
MalwareShadowPad | ShadowPad has discovered system information including memory status, CPU frequency, and OS versions. |
| T1082 System Information Discovery |
MalwareAstaroth | Astaroth collects the machine name and keyboard language from the system. |
| T1082 System Information Discovery |
MalwareQakBot | QakBot can collect system information including the OS version and domain on a compromised host. |
| T1082 System Information Discovery |
MalwareSYSCON | SYSCON has the ability to use Systeminfo to identify system information. |
| T1082 System Information Discovery |
MalwareGelsemium | Gelsemium can determine the operating system and whether a targeted machine has a 32 or 64 bit architecture. |
| T1082 System Information Discovery |
MalwarejRAT | jRAT collects information about the OS (version, build type, install date) as well as system up-time upon receiving a connection from a backdoor. |
| T1082 System Information Discovery |
MalwareDridex | Dridex has collected the computer name and OS architecture information from the system. |
| T1082 System Information Discovery |
MalwareOSX/Shlayer | OSX/Shlayer has collected the IOPlatformUUID, session UID, and the OS version using the command |
| T1082 System Information Discovery |
MalwareDenis | Denis collects OS information and the computer name from the victim’s machine. |
| T1082 System Information Discovery |
MalwareSplatCloak | SplatCloak has collected the Windows build number using the windows kernel API `RtlGetVersion` to determine if the response is 19000 or higher (Windows 10 version 2004 or later). |
| T1082 System Information Discovery |
MalwareComnie | Comnie collects the hostname of the victim machine. |
| T1082 System Information Discovery |
MalwareOSInfo | OSInfo discovers information about the infected machine. |
| T1082 System Information Discovery |
MalwareLizar | Lizar can collect the computer name from the machine. |
| T1082 System Information Discovery |
MalwareDtrack | Dtrack can collect the victim's computer name, hostname and adapter information to create a unique identifier. |
| T1082 System Information Discovery |
MalwareLoudMiner | LoudMiner has monitored CPU usage. |
| T1082 System Information Discovery |
MalwareAzorult | Azorult can collect the machine information, system architecture, the OS version, computer name, Windows product name, the number of CPU cores, video card information, and the system language. |
| T1082 System Information Discovery |
MalwareBACKSPACE | During its initial execution, BACKSPACE extracts operating system information from the infected host. |
| T1082 System Information Discovery |
MalwareUPPERCUT | UPPERCUT has the capability to gather the system’s hostname and OS version. |
| T1082 System Information Discovery |
MalwareADVSTORESHELL | ADVSTORESHELL can run Systeminfo to gather information about the victim. |
| T1082 System Information Discovery |
MalwareStrifeWater | StrifeWater can collect the OS version, architecture, and machine name to create a unique token for the infected host. |
| T1082 System Information Discovery |
MalwareWarzoneRAT | WarzoneRAT can collect compromised host information, including OS version, PC name, RAM size, and CPU details. |
| T1082 System Information Discovery |
MalwareSLOTHFULMEDIA | SLOTHFULMEDIA has collected system name, OS version, adapter information, and memory usage from a victim machine. |
| T1082 System Information Discovery |
MalwareFALLCHILL | FALLCHILL can collect operating system (OS) version information, processor information, and system name from the victim. |
| T1082 System Information Discovery |
MalwareXORIndex Loader | XORIndex Loader has the ability to collect the hostname, OS Username, Geolocation, and OS version of an infected host. |
| T1082 System Information Discovery |
ToolCovenant | Covenant implants can gather basic information on infected systems. |
| T1082 System Information Discovery |
ToolDiskpart | Diskpart can show information about the selected disk, partition, volume, or virtual hard disk (VHD). |
| T1082 System Information Discovery |
ToolShimRatReporter | ShimRatReporter gathered the operating system name and specific Windows version of an infected machine. |
| T1082 System Information Discovery |
ToolSILENTTRINITY | SILENTTRINITY can collect information related to a compromised host, including OS version. |
| T1082 System Information Discovery |
ToolEmpire | Empire can enumerate host system information like OS, architecture, domain name, applied patches, and more. |
| T1082 System Information Discovery |
Tooldsquery | dsquery has the ability to enumerate various information, such as the operating system and host name, for systems within a domain. |
| T1082 System Information Discovery |
ToolPoshC2 | PoshC2 contains modules, such as |
| T1082 System Information Discovery |
ToolRemcos | Remcos can collect the OS version and process architecture of compromised hosts. |
| T1082 System Information Discovery |
ToolSysteminfo | Systeminfo can be used to gather information about the operating system. |
| T1082 System Information Discovery |
Toolcmd | cmd can be used to find information about the operating system. |
| T1082 System Information Discovery |
ToolKoadic | Koadic can obtain the OS version and build, computer name, and processor architecture from a compromised host. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.