System Information Discovery

T1082

Technique.View on attack.mitre.org

About this technique

An adversary may attempt to get detailed information about the operating system and hardware, including version, patches, hotfixes, service packs, and architecture. Adversaries may use this information to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions. This behavior is distinct from Local Storage Discovery which is an adversary's discovery of local drive, disks and/or volumes.

Tools such as Systeminfo can be used to gather detailed system information. If running with privileged access, a breakdown of system data can be gathered through the systemsetup configuration tool on macOS. Adversaries may leverage a Network Device CLI on network devices to gather detailed system information (e.g. show version). On ESXi servers, threat actors may gather system information from various esxcli utilities, such as `system hostname get` and `system version get`.

Infrastructure as a Service (IaaS) cloud providers such as AWS, GCP, and Azure allow access to instance and virtual machine information via APIs. Successful authenticated API calls can return data such as the operating system platform and status of a particular instance or the model view of a virtual machine.

System Information Discovery combined with information gathered from other forms of discovery and reconnaissance can drive payload development and concealment.

Detection rules49

Rules on DetectionCode tagged with T1082.

Sigma31

RuleLevelLog source
HackTool - PCHunter Executionhighwindows / process_creation
HackTool - winPEAS Executionhighwindows / process_creation
HackTool - WinPwn Executionhighwindows / process_creation
HackTool - WinPwn Execution - ScriptBlockhighwindows / ps_script
Network Reconnaissance Activityhighwindows / process_creation
Potential GobRAT File Discovery Via Grephighlinux / process_creation
Suspicious Kernel Dump Using Dtracehighwindows / process_creation
Bitbucket User Details Export Attempt Detectedmediumbitbucket / NULL
Bitbucket User Permissions Export Attemptmediumbitbucket / NULL
Potential Product Class Reconnaissance Via Wmic.EXEmediumwindows / process_creation
Potential Suspicious Activity Using SeCEditmediumwindows / process_creation
PUA - System Informer Executionmediumwindows / process_creation
System Disk And Volume Reconnaissance Via Wmic.EXEmediumwindows / process_creation
System Information Discovery Using Ioregmediummacos / process_creation
System Information Discovery Using sw_versmediummacos / process_creation

Splunk18

RuleTypeRiskData source
Cisco ASA - Reconnaissance Command ActivityAnomalyNULLCisco ASA Logs
Cisco IOS XE Reconnaissance Command ActivityAnomalyNULLCisco IOS Logs
Detect attackers scanning for vulnerable JBoss serversTTPNULL
ESXi System Information DiscoveryTTPNULLVMWare ESXi Syslog
Linux Auditd Kernel Module EnumerationAnomalyNULLLinux Auditd Syscall
Linux Kernel Module EnumerationAnomalyNULLSysmon for Linux EventID 1
System Information Discovery DetectionTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Web Servers Executing Suspicious ProcessesTTPNULLSysmon EventID 1
Windows Information Discovery FsutilAnomalyNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Windows Post Exploitation Risk BehaviorCorrelationNULL
Windows PowerShell Invoke-RestMethod IP Information CollectionAnomalyNULLPowershell Script Block Logging 4104
Windows PsTools Recon UsageAnomalyNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Windows WinPEAS PowerShell Script ExecutionTTPNULLPowershell Script Block Logging 4104
Windows Wmic CPU DiscoveryAnomalyNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Windows Wmic DiskDrive DiscoveryAnomalyNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2

Groups58

Show 34 more

Software355

Show 331 more
BankshotBazarBeaverTailBISCUITBisonalBlack BastaBlackByte RansomwareBlackCatBlackEnergyBLINDINGCANBLUELIGHTBOLDMOVEBonadanBoomBoxBrave PrinceBUBBLEWRAPBumblebeeBundloreCaddyWiperCadelspyCannonCarberpCardinal RATCARROTBATCaterpillar WebShellChaesCharmPowerChChesChrommmeClamblingcmdComnieCORESHELLCovenantCozyCarCrimsonCuckoo StealerCyclops BlinkDarkCometDarkGateDarkTortillaDarkWatchmanDEADEYEDenisDerusbiDiavolDiskpartDownPaperDridexDropBookdsqueryDtrackDUSTTRAPDustySkyDyreEgregorEliseEmissaryEmpireEnvyScoutEpicEVILNUMExplosiveFALLCHILLFatDukeFelismusFELIXROOTFerociousFinal1stspyFinFisherFlawedAmmyyFysbisGelsemiumGet2gh0st RATGlassWormGold DragonGoldenSpyGomirGootloaderGrandoreiroGravityRATGreen LambertGRIFFONGrimAgentHALFBAKEDHAPPYWORKHavocHAWKBALLHermeticWiperHexEval LoaderHiddenFaceHildegardHOPLIGHTHotCroissantHydraqIceAppleIcedIDIMAPLoaderIndustroyerInnaputRATInvisibleFerretInvisiMoleIronWindIxesheJPINjRATKapekaKARAEKasidetKazuarKerrdownKesselKevinKeyBoyKEYMARBLEKoadicKobalosKOCTOPUSKOMPROGOKONNIKwampirsLAMEHUGLatrodectusLazyWiperLightNeuronLightSpyLine DancerLinfoLiteDukeLitePowerLITTLELAMB.WOOLTEALizarLockBit 2.0LockBit 3.0LODEINFOLokibotLoudMinerLuciferLumma StealerLunarMailLunarWebMacheteMacMamacOS.OSAMinerMafaldaMagicRATMangoManjusakaMarkiRATMazeMedusa RansomwaremetaMainMetamorfoMeteorMicropsiaMilanMini Shai-HuludMiniDukeMirageFoxMis-TypeMisdatMispaduMobileOrderMoleNetMongallMoonWindMore_eggsMURKYTOPNaidNanHaiShuNavRATNDiskMonitorNeoichorNetwalkerNETWIRENightdoorNinjanjRATNKAbuseNOKKINOOPLDRObliqueRATOceanSaltOctopusOilBoosterOkrumOopsIEOrzOSInfoOSX_OCEANLOTUS.DOSX/ShlayerPasamPay2KeyPenquinPikabotPinchDukePingPullPipeMonPisloaderPLAINTEEPlugXPoetRATPonyPOORAIMPoshC2PowerDukePowerShowerPOWERSTATSPOWRUNERPrikormkaProxysvcPUBLOADPUNCHBUGGYPupyPureCrypterQakBotQilinQuasarRATRaccoon StealerRansomHubRaspberry RobinRATANKBARCSessionReaverRedLeavesRedLine StealerRemcosRemsecRevenge RATREvilRifdoorRIFLESPINERising SunRogueRobinROKRATRotaJakiroRoyalRTMRunningRATRustyWaterS-TypeSagerunexSaint BotSampleCheck5000SardonicSDBbotServHelperShadowPadShai-HuludShamoonSharkSharpStageSHARPSTATSShimRatReporterShrinkLockerSHUTTERSPEEDSideTwistSILENTTRINITYSkidmapSLOTHFULMEDIASLOWDRIFTSMOKEDHAMSnip3SocGholishSodaMasterSolarSombRATSoreFangSOUNDBITESparkSPAWNCHIMERASpeakUpSpicyOmeletteSplatCloakSquirrelwaffleSslMMSTARWHALEStealBitStoneDrillStreamExStrelaStealerStrifeWaterStuxnetSUNBURSTSVCReadySynAckSys10SYSCONSystemBCSysteminfoSysUpdateT9000TajMahalTeamPCP Cloud StealerThreatNeedleTONESHELLTrickBotTrojan.KaraganyTroll StealerTsundere BotnetTurianTURNEDUPUnknown LoggerUPPERCUTUroburosUrsnifValakVERMINVolgmerWarzoneRATWellMessWINDSHIELDWINERACKWingbirdWinMMWinnti for WindowsWoody RATXAgentOSXXCSSETXLoaderXORIndex LoaderYAHOYAHytyZebrocyZeroTZeus PandaZLibzwShellZxShellZxxZ

Campaigns14

Procedure examples427

Groups58

Used byProcedure example
Groupadmin@338

admin@338 actors used the following commands after exploiting a machine with LOWBALL malware to obtain information about the OS: ver >> %temp%\download systeminfo >> %temp%\download

GroupAPT18

APT18 can collect system information from the victim’s machine.

GroupAPT19

APT19 collected system architecture information. APT19 used an HTTP malware variant and a Port 22 malware variant to gather the hostname and CPU information from the victim’s machine.

GroupAPT3

APT3 has a tool that can obtain information about the local system.

GroupAPT32

APT32 has collected the OS version and computer name from victims. One of the group's backdoors can also query the Windows Registry to gather system information, and another macOS backdoor performs a fingerprint of the machine on its first connection to the C&C server. APT32 executed shellcode to identify the name of the infected host.

GroupAPT37

APT37 collects the computer name, the BIOS model, and execution path.

GroupAPT38

APT38 has attempted to get detailed information about a compromised host, including the operating system, version, patches, hotfixes, and service packs.

GroupAPT41

APT41 uses multiple built-in commands such as systeminfo and `net config Workstation` to enumerate victim system basic configuration information.

View all 58 groups examples

Software355

Used byProcedure example
Malware4H RAT

4H RAT sends an OS version identifier in its beacons.

MalwareAcidPour

AcidPour can identify various system locations and mapped devices on Linux systems as a precursor to wiping activity.

MalwareAction RAT

Action RAT has the ability to collect the hostname, OS version, and OS architecture of an infected host.

MalwareADVSTORESHELL

ADVSTORESHELL can run Systeminfo to gather information about the victim.

MalwareAgent Tesla

Agent Tesla can collect the system's computer name and also has the capability to collect information on the processor, memory, OS, and video card from the system.

MalwareAkira

Akira uses the GetSystemInfo Windows function to determine the number of processors on a victim machine.

MalwareAmadey

Amadey has collected the computer name and OS version from a compromised machine.

MalwareAnchor

Anchor can determine the hostname and linux version on a compromised host.

View all 355 software examples

Campaigns14

Used byProcedure example
CampaignAnthropic AI-orchestrated Campaign

During the Anthropic AI-orchestrated Campaign, the adversary tasked Claude Code to query databases and systems in order to identify proprietary information, including system configurations and database types.

CampaignArcaneDoor

ArcaneDoor included collection of victim device configuration information.

CampaignCutting Edge

During Cutting Edge, threat actors used the ENUM4LINUX Perl script for discovery on Windows and Samba hosts.

CampaignFrankenstein

During Frankenstein, the threat actors used Empire to obtain the compromised machine's name.

CampaignFunnyDream

During FunnyDream, the threat actors used Systeminfo to collect information on targeted hosts.

CampaignJuicy Mix

During Juicy Mix, OilRig used a script to send the name of the compromised host via HTTP `POST` to register it with C2.

CampaignKV Botnet Activity

KV Botnet Activity includes use of native system tools, such as uname, to obtain information about victim device architecture, as well as gathering other system information such as the victim's hosts file and CPU utilization.

CampaignLeviathan Australian Intrusions

Leviathan performed host enumeration and data gathering operations on victim machines during Leviathan Australian Intrusions.

View all 14 campaigns examples

References8

  1. 20 macOS Common Tools and Techniques Open source
    Phil Stokes. (2021, February 16). 20 Common Tools & Techniques Used by macOS Threat Actors & Malware. Retrieved August 23, 2021.
  2. Amazon Describe Instance Open source
    Amazon. (n.d.). describe-instance-information. Retrieved March 3, 2020.
  3. Crowdstrike Hypervisor Jackpotting Pt 2 2021 Open source
    Michael Dawson. (2021, August 30). Hypervisor Jackpotting, Part 2: eCrime Actors Increase Targeting of ESXi Servers with Ransomware. Retrieved March 26, 2025.
  4. Google Instances Resource Open source
    Google. (n.d.). Rest Resource: instance. Retrieved March 3, 2020.
  5. Microsoft Virutal Machine API Open source
    Microsoft. (2019, March 1). Virtual Machines - Get. Retrieved October 8, 2019.
  6. OSX.FairyTale Open source
    Phile Stokes. (2018, September 20). On the Trail of OSX.FairyTale | Adware Playing at Malware. Retrieved August 24, 2021.
  7. US-CERT-TA18-106A Open source
    US-CERT. (2018, April 20). Alert (TA18-106A) Russian State-Sponsored Cyber Actors Targeting Network Infrastructure Devices. Retrieved October 19, 2020.
  8. Varonis Open source
    Jason Hill. (2023, February 8). VMware ESXi in the Line of Ransomware Fire. Retrieved March 26, 2025.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.