ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1082×

355 examples

TechniqueUsed byProcedure example
T1082
System Information Discovery
MalwareTrickBot

TrickBot gathers the OS version, machine name, CPU type, amount of RAM available, and UEFI/BIOS firmware information from the victim’s machine.

T1082
System Information Discovery
MalwarePowerDuke

PowerDuke has commands to get information about the victim's name, build, version, serial number, and memory usage.

T1082
System Information Discovery
MalwareBLINDINGCAN

BLINDINGCAN has collected from a victim machine the system name, processor information, and OS version.

T1082
System Information Discovery
MalwareNinja

Ninja can obtain the computer name and information on the OS from targeted hosts.

T1082
System Information Discovery
MalwarePikabot

Pikabot performs a variety of system checks and gathers system information, including commands such as whoami.

T1082
System Information Discovery
MalwareRCSession

RCSession can gather system information from a compromised host.

T1082
System Information Discovery
MalwareSpark

Spark can collect the hostname, keyboard layout, and language from the system.

T1082
System Information Discovery
MalwareSynAck

SynAck gathers computer names, OS version info, and also checks installed keyboard layouts to estimate if it has been launched from a certain list of countries.

T1082
System Information Discovery
MalwareBumblebee

Bumblebee can enumerate the OS version and domain on a targeted system.

T1082
System Information Discovery
MalwareMURKYTOP

MURKYTOP has the capability to retrieve information about the OS.

T1082
System Information Discovery
MalwareGRIFFON

GRIFFON has used a reconnaissance module that can be used to retrieve information about a victim's computer, including the resolution of the workstation .

T1082
System Information Discovery
MalwareAmadey

Amadey has collected the computer name and OS version from a compromised machine.

T1082
System Information Discovery
MalwareProxysvc

Proxysvc collects the OS version, country name, MAC address, computer name, and physical memory statistics.

T1082
System Information Discovery
MalwareOrz

Orz can gather the victim OS version and whether it is 64 or 32 bit.

T1082
System Information Discovery
MalwareNOKKI

NOKKI can gather information on the operating system on the victim’s machine.

T1082
System Information Discovery
Malwareyty

yty gathers the computer name, CPU information, Microsoft Windows version, and runs the command systeminfo.

T1082
System Information Discovery
MalwareBackdoor.Oldrea

Backdoor.Oldrea collects information about the OS and computer name.

T1082
System Information Discovery
MalwareStuxnet

Stuxnet collects system information including computer and domain names, OS version, and S7P paths.

T1082
System Information Discovery
MalwareIronWind

IronWind can capture the OS version and computer name of the compromised host.

T1082
System Information Discovery
MalwareRotaJakiro

RotaJakiro executes a set of commands to collect device information, including `uname`. Another example is the `cat /etc/*release | uniq` command used to collect the current OS distribution.

T1082
System Information Discovery
MalwareGet2

Get2 has the ability to identify the computer name and Windows version of an infected host.

T1082
System Information Discovery
MalwarePOWRUNER

POWRUNER may collect information about the system by running hostname and systeminfo on a victim.

T1082
System Information Discovery
MalwareSharpStage

SharpStage has checked the system settings to see if Arabic is the configured language.

T1082
System Information Discovery
MalwareSardonic

Sardonic has the ability to collect the computer name, and CPU manufacturer name from a compromised machine. Sardonic also has the ability to execute the `ver` and `systeminfo` commands.

T1082
System Information Discovery
MalwareHALFBAKED

HALFBAKED can obtain information about the OS, processor, and BIOS.

T1082
System Information Discovery
MalwareMisdat

The initial beacon packet for Misdat contains the operating system version of the victim.

T1082
System Information Discovery
MalwareEmissary

Emissary has the capability to execute ver and systeminfo commands.

T1082
System Information Discovery
MalwareKEYMARBLE

KEYMARBLE has the capability to collect the computer name, language settings, the OS version, CPU information, and time elapsed since system start.

T1082
System Information Discovery
MalwareBUBBLEWRAP

BUBBLEWRAP collects system information, including the operating system version and hostname.

T1082
System Information Discovery
MalwareHAWKBALL

HAWKBALL can collect the OS version, architecture information, and computer name.

T1082
System Information Discovery
MalwareUrsnif

Ursnif has used Systeminfo to gather system information.

T1082
System Information Discovery
MalwareThreatNeedle

ThreatNeedle can collect system profile information from a compromised host.

T1082
System Information Discovery
MalwareRansomHub

RansomHub can retrieve information about virtual machines.

T1082
System Information Discovery
MalwareZLib

ZLib has the ability to enumerate system information.

T1082
System Information Discovery
MalwareRedLeaves

RedLeaves can gather extended system information including the hostname, OS version number, platform, memory information, time elapsed since system startup, and CPU information.

T1082
System Information Discovery
MalwareTsundere Botnet

Tsundere Botnet has collected the machine’s MAC address, total memory, GPU information and other system information.

T1082
System Information Discovery
MalwareLITTLELAMB.WOOLTEA

LITTLELAMB.WOOLTEA can check the type of Ivanti VPN device it is running on by executing `first_run()` to identify the first four bytes of the motherboard serial number.

T1082
System Information Discovery
MalwareFelismus

Felismus collects the system information, including hostname and OS version, and sends it to the C2 server.

T1082
System Information Discovery
MalwareZeus Panda

Zeus Panda collects the OS version, system architecture, computer name, product ID, install date, and information on the keyboard mapping to determine the language used on the system.

T1082
System Information Discovery
MalwareHavoc

Havoc can gather system information including hostname, domain, and OS details.

T1082
System Information Discovery
MalwareCARROTBAT

CARROTBAT has the ability to determine the operating system of the compromised host and whether Windows is being run with x86 or x64 architecture.

T1082
System Information Discovery
MalwareGravityRAT

GravityRAT collects the MAC address, computer name, and CPU information.

T1082
System Information Discovery
MalwareInvisibleFerret

InvisibleFerret has collected OS type, hostname and system version through the "pay" module. InvisibleFerret has also queried the victim device using Python scripts to obtain the User and Hostname.

T1082
System Information Discovery
MalwareBankshot

Bankshot gathers system information, network addresses, and the operation system version.

T1082
System Information Discovery
MalwareHAPPYWORK

can collect system information, including computer name, system manufacturer, IsDebuggerPresent state, and execution path.

T1082
System Information Discovery
MalwarePLAINTEE

PLAINTEE collects general system enumeration data about the infected machine and checks the OS version.

T1082
System Information Discovery
MalwarePony

Pony has collected the Service Pack, language, and region information to send to the C2.

T1082
System Information Discovery
MalwareWinMM

WinMM collects the system name, OS version including service pack, and system install date and sends the information to the C2 server.

T1082
System Information Discovery
MalwareTONESHELL

TONESHELL has the ability to retrieve the name of the infected machine.

T1082
System Information Discovery
MalwareKasidet

Kasidet has the ability to obtain a victim's system name and operating system version.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.