ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1082×

58 examples

TechniqueUsed byProcedure example
T1082
System Information Discovery
GroupAPT38

APT38 has attempted to get detailed information about a compromised host, including the operating system, version, patches, hotfixes, and service packs.

T1082
System Information Discovery
GroupBlackByte

BlackByte used various system commands and tools to pull system information during operations.

T1082
System Information Discovery
GroupSideCopy

SideCopy has identified the OS version of a compromised host.

T1082
System Information Discovery
GroupAPT3

APT3 has a tool that can obtain information about the local system.

T1082
System Information Discovery
GroupMustard Tempest

Mustard Tempest has used implants to perform system reconnaissance on targeted systems.

T1082
System Information Discovery
GroupKimsuky

Kimsuky has enumerated OS type, OS version, and other information using a script or the "systeminfo" command. Kimsuky has also obtained system information such as OS type, OS version, and system type through querying various Windows Management Instrumentation (WMI) classes including `Win32_OperatingSystem`.

T1082
System Information Discovery
Groupadmin@338

admin@338 actors used the following commands after exploiting a machine with LOWBALL malware to obtain information about the OS: ver >> %temp%\download systeminfo >> %temp%\download

T1082
System Information Discovery
GroupPatchwork

Patchwork collected the victim computer name, OS version, and architecture type and sent the information to its C2 server.

T1082
System Information Discovery
GroupAPT41

APT41 uses multiple built-in commands such as systeminfo and `net config Workstation` to enumerate victim system basic configuration information.

T1082
System Information Discovery
GroupAPT32

APT32 has collected the OS version and computer name from victims. One of the group's backdoors can also query the Windows Registry to gather system information, and another macOS backdoor performs a fingerprint of the machine on its first connection to the C&C server. APT32 executed shellcode to identify the name of the infected host.

T1082
System Information Discovery
GroupMuddyWater

MuddyWater has used malware that can collect the victim’s OS version and machine name.

T1082
System Information Discovery
GroupGamaredon Group

A Gamaredon Group file stealer can gather the victim's computer name and drive serial numbers to send to a C2 server.

T1082
System Information Discovery
GroupTeamTNT

TeamTNT has searched for system version, architecture, and hostname information.

T1082
System Information Discovery
GroupFIN7

FIN7 has used csvde.exe, which is a built-in Windows command line tool, to export system information. Additionally, WsTaskLoad has gathered system information, such as operating system and hostname.

T1082
System Information Discovery
GroupSandworm Team

Sandworm Team used a backdoor to enumerate information about the infected system's operating system.

T1082
System Information Discovery
GroupAPT18

APT18 can collect system information from the victim’s machine.

T1082
System Information Discovery
GroupCURIUM

CURIUM deploys information gathering tools focused on capturing IP configuration, running application, system information, and network connectivity information.

T1082
System Information Discovery
GroupSidewinder

Sidewinder has used tools to collect the computer name, OS version, installed hotfixes, as well as information regarding the memory and processor on a compromised host.

T1082
System Information Discovery
GroupMustang Panda

Mustang Panda has gathered system information using systeminfo.

T1082
System Information Discovery
GroupZIRCONIUM

ZIRCONIUM has used a tool to capture the processor architecture of a compromised host in order to register it with C2.

T1082
System Information Discovery
GroupRocke

Rocke has used uname -m to collect the name and information about the infected system's kernel.

T1082
System Information Discovery
GroupScattered Spider

Scattered Spider has executed scripts to identify the underlying operating system to ensure it uses the correct installation package for malicious payloads.

T1082
System Information Discovery
GroupContagious Interview

Contagious Interview has configured malicious webpages to identify the victim’s operating system by reviewing the details of the victims User-Agent of their browser.

T1082
System Information Discovery
GroupTA2541

TA2541 has collected system information prior to downloading malware on the targeted host.

T1082
System Information Discovery
GroupAPT37

APT37 collects the computer name, the BIOS model, and execution path.

T1082
System Information Discovery
GroupMoses Staff

Moses Staff collected information about the infected host, including the machine names and OS architecture.

T1082
System Information Discovery
GroupOilRig

OilRig has run hostname and systeminfo on a victim.

T1082
System Information Discovery
GroupWindigo

Windigo has used a script to detect which Linux distribution and version is currently installed on the system.

T1082
System Information Discovery
GroupHigaisa

Higaisa collected the system GUID and computer name.

T1082
System Information Discovery
GroupTropic Trooper

Tropic Trooper has detected a target system’s OS version.

T1082
System Information Discovery
GroupAquatic Panda

Aquatic Panda has used native OS commands to understand privilege levels and system details.

T1082
System Information Discovery
GroupKe3chang

Ke3chang performs operating system information discovery using systeminfo and has used implants to identify the system language and computer name.

T1082
System Information Discovery
GroupBlue Mockingbird

Blue Mockingbird has collected hardware details for the victim's system, including CPU and memory information.

T1082
System Information Discovery
GroupWinter Vivern

Winter Vivern script execution includes basic victim information gathering steps which are then transmitted to command and control servers.

T1082
System Information Discovery
GroupTurla

Turla surveys a system upon check-in to discover operating system configuration details using the systeminfo and set commands.

T1082
System Information Discovery
GroupStorm-0501

Storm-0501 has leveraged native Windows tools and commands such as `systeminfo` and open-source tools including OSQuery and ossec-win32 to query details about the endpoint.

T1082
System Information Discovery
GroupRedCurl

RedCurl has collected information about the target system, such as system information and list of network connections.

T1082
System Information Discovery
GroupStealth Falcon

Stealth Falcon malware gathers system information via WMI, including the system directory, build number, serial number, version, manufacturer, model, and total physical memory.

T1082
System Information Discovery
GroupMirrorFace

MirrorFace has employed malicious macros and native Windows tools such as csvde.exe, nltest.exe and quser.exe for discovery.

T1082
System Information Discovery
GroupMedusa Group

Medusa Group has leveraged `cmd.exe` to identify system info `cmd.exe /c systeminfo`.

T1082
System Information Discovery
GroupDarkhotel

Darkhotel has collected the hostname, OS version, service pack version, and the processor architecture from the victim’s machine.

T1082
System Information Discovery
GroupWindshift

Windshift has used malware to identify the computer name of a compromised host.

T1082
System Information Discovery
GroupMalteiro

Malteiro collects the machine information, system architecture, the OS version, computer name, and Windows product name.

T1082
System Information Discovery
GroupAPT42

APT42 has used malware, such as GHAMBAR and POWERPOST, to collect system information.

T1082
System Information Discovery
GroupLazarus Group

Several Lazarus Group malware families collect information on the type and version of the victim OS, as well as the victim computer name and CPU information.

T1082
System Information Discovery
GroupSowbug

Sowbug obtained OS version and hardware configuration from a victim.

T1082
System Information Discovery
GroupWizard Spider

Wizard Spider has used Systeminfo and similar commands to acquire detailed configuration information of a victim's machine. Wizard Spider has also utilized the PowerShell cmdlet `Get-ADComputer` to collect DNS hostnames, last logon dates, and operating system information from Active Directory.

T1082
System Information Discovery
GroupMoonstone Sleet

Moonstone Sleet has gathered information on victim systems.

T1082
System Information Discovery
GroupInception

Inception has used a reconnaissance module to gather information about the operating system and hardware on the infected host.

T1082
System Information Discovery
GroupVOID MANTICORE

VOID MANTICORE has gathered system information and disseminated it back to C2.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.