Real-world descriptions of how a group, tool or campaign used a technique.
355 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1082 System Information Discovery |
ToolPupy | Pupy can grab a system’s information including the OS version, architecture, etc. |
| T1082 System Information Discovery |
ToolQuasarRAT | QuasarRAT can gather system information from the victim’s machine including the OS type. |
| T1082 System Information Discovery |
MalwareTeamPCP Cloud Stealer | TeamPCP Cloud Stealer has detected if it is on a developer machine by checking if the environmental variable GITHUB_ACTIONS != “true”. TeamPCP Cloud Stealer has also identified readable memory regions on CI/CD runners and enumerated system information using `hostname` and `uname-a`. |
| T1082 System Information Discovery |
MalwareMini Shai-Hulud | Mini Shai-Hulud has gathered system information of victim hosts through the use of common discovery commands to include `hostname`, `uname-a` and `printenv`. Mini Shai-Hulud has also conducted system checks of the victim device to include enumerating the system type and the number of CPUs operating on victim host. |
| T1082 System Information Discovery |
MalwareBADFLICK | BADFLICK has captured victim computer name, memory space, and CPU details. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.