Real-world descriptions of how a group, tool or campaign used a technique.
14 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1082 System Information Discovery |
CampaignKV Botnet Activity | KV Botnet Activity includes use of native system tools, such as |
| T1082 System Information Discovery |
CampaignSharePoint ToolShell Exploitation | During SharePoint ToolShell Exploitation, threat actors fingerprinted targeted SharePoint servers to identify OS version and running processes. |
| T1082 System Information Discovery |
CampaignFrankenstein | During Frankenstein, the threat actors used Empire to obtain the compromised machine's name. |
| T1082 System Information Discovery |
CampaignRedDelta Modified PlugX Infection Chain Operations | Mustang Panda captured victim operating system type via User Agent analysis during RedDelta Modified PlugX Infection Chain Operations. |
| T1082 System Information Discovery |
CampaignOperation Honeybee | During Operation Honeybee, the threat actors collected the computer name, OS, and other system information using `cmd /c systeminfo > %temp%\ temp.ini`. |
| T1082 System Information Discovery |
CampaignCutting Edge | During Cutting Edge, threat actors used the ENUM4LINUX Perl script for discovery on Windows and Samba hosts. |
| T1082 System Information Discovery |
CampaignAnthropic AI-orchestrated Campaign | During the Anthropic AI-orchestrated Campaign, the adversary tasked Claude Code to query databases and systems in order to identify proprietary information, including system configurations and database types. |
| T1082 System Information Discovery |
CampaignJuicy Mix | During Juicy Mix, OilRig used a script to send the name of the compromised host via HTTP `POST` to register it with C2. |
| T1082 System Information Discovery |
CampaignOperation AkaiRyū | During Operation AkaiRyū, MirrorFace collected system information. |
| T1082 System Information Discovery |
CampaignFunnyDream | During FunnyDream, the threat actors used Systeminfo to collect information on targeted hosts. |
| T1082 System Information Discovery |
CampaignOperation CuckooBees | During Operation CuckooBees, the threat actors used the `systeminfo` command to gather details about a compromised system. |
| T1082 System Information Discovery |
CampaignArcaneDoor | ArcaneDoor included collection of victim device configuration information. |
| T1082 System Information Discovery |
CampaignOperation Wocao | During Operation Wocao, threat actors discovered the OS versions of systems connected to a targeted network. |
| T1082 System Information Discovery |
CampaignLeviathan Australian Intrusions | Leviathan performed host enumeration and data gathering operations on victim machines during Leviathan Australian Intrusions. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.