ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1082×

355 examples

TechniqueUsed byProcedure example
T1082
System Information Discovery
ToolPupy

Pupy can grab a system’s information including the OS version, architecture, etc.

T1082
System Information Discovery
ToolQuasarRAT

QuasarRAT can gather system information from the victim’s machine including the OS type.

T1082
System Information Discovery
MalwareTeamPCP Cloud Stealer

TeamPCP Cloud Stealer has detected if it is on a developer machine by checking if the environmental variable  GITHUB_ACTIONS != “true”. TeamPCP Cloud Stealer has also identified readable memory regions on CI/CD runners and enumerated system information using `hostname` and `uname-a`.

T1082
System Information Discovery
MalwareMini Shai-Hulud

Mini Shai-Hulud has gathered system information of victim hosts through the use of common discovery commands to include `hostname`, `uname-a` and `printenv`. Mini Shai-Hulud has also conducted system checks of the victim device to include enumerating the system type and the number of CPUs operating on victim host.

T1082
System Information Discovery
MalwareBADFLICK

BADFLICK has captured victim computer name, memory space, and CPU details.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.