Technique.View on attack.mitre.org
An adversary may attempt to get detailed information about the operating system and hardware, including version, patches, hotfixes, service packs, and architecture. Adversaries may use this information to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions. This behavior is distinct from Local Storage Discovery which is an adversary's discovery of local drive, disks and/or volumes.
Tools such as Systeminfo can be used to gather detailed system information. If running with privileged access, a breakdown of system data can be gathered through the systemsetup configuration tool on macOS. Adversaries may leverage a Network Device CLI on network devices to gather detailed system information (e.g. show version). On ESXi servers, threat actors may gather system information from various esxcli utilities, such as `system hostname get` and `system version get`.
Infrastructure as a Service (IaaS) cloud providers such as AWS, GCP, and Azure allow access to instance and virtual machine information via APIs. Successful authenticated API calls can return data such as the operating system platform and status of a particular instance or the model view of a virtual machine.
System Information Discovery combined with information gathered from other forms of discovery and reconnaissance can drive payload development and concealment.
Rules on DetectionCode tagged with T1082.
| Rule | Type | Risk | Data source |
|---|---|---|---|
| Cisco ASA - Reconnaissance Command Activity | Anomaly | NULL | Cisco ASA Logs |
| Cisco IOS XE Reconnaissance Command Activity | Anomaly | NULL | Cisco IOS Logs |
| Detect attackers scanning for vulnerable JBoss servers | TTP | NULL | |
| ESXi System Information Discovery | TTP | NULL | VMWare ESXi Syslog |
| Linux Auditd Kernel Module Enumeration | Anomaly | NULL | Linux Auditd Syscall |
| Linux Kernel Module Enumeration | Anomaly | NULL | Sysmon for Linux EventID 1 |
| System Information Discovery Detection | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Web Servers Executing Suspicious Processes | TTP | NULL | Sysmon EventID 1 |
| Windows Information Discovery Fsutil | Anomaly | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Windows Post Exploitation Risk Behavior | Correlation | NULL | |
| Windows PowerShell Invoke-RestMethod IP Information Collection | Anomaly | NULL | Powershell Script Block Logging 4104 |
| Windows PsTools Recon Usage | Anomaly | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Windows WinPEAS PowerShell Script Execution | TTP | NULL | Powershell Script Block Logging 4104 |
| Windows Wmic CPU Discovery | Anomaly | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Windows Wmic DiskDrive Discovery | Anomaly | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Windows Wmic Memory Chip Discovery | Anomaly | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Windows Wmic Network Discovery | Anomaly | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Windows Wmic Systeminfo Discovery | Anomaly | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Used by | Procedure example |
|---|---|
| Groupadmin@338 | admin@338 actors used the following commands after exploiting a machine with LOWBALL malware to obtain information about the OS: |
| GroupAPT18 | APT18 can collect system information from the victim’s machine. |
| GroupAPT19 | APT19 collected system architecture information. APT19 used an HTTP malware variant and a Port 22 malware variant to gather the hostname and CPU information from the victim’s machine. |
| GroupAPT3 | APT3 has a tool that can obtain information about the local system. |
| GroupAPT32 | APT32 has collected the OS version and computer name from victims. One of the group's backdoors can also query the Windows Registry to gather system information, and another macOS backdoor performs a fingerprint of the machine on its first connection to the C&C server. APT32 executed shellcode to identify the name of the infected host. |
| GroupAPT37 | APT37 collects the computer name, the BIOS model, and execution path. |
| GroupAPT38 | APT38 has attempted to get detailed information about a compromised host, including the operating system, version, patches, hotfixes, and service packs. |
| GroupAPT41 | APT41 uses multiple built-in commands such as |
| Used by | Procedure example |
|---|---|
| Malware4H RAT | 4H RAT sends an OS version identifier in its beacons. |
| MalwareAcidPour | AcidPour can identify various system locations and mapped devices on Linux systems as a precursor to wiping activity. |
| MalwareAction RAT | Action RAT has the ability to collect the hostname, OS version, and OS architecture of an infected host. |
| MalwareADVSTORESHELL | ADVSTORESHELL can run Systeminfo to gather information about the victim. |
| MalwareAgent Tesla | Agent Tesla can collect the system's computer name and also has the capability to collect information on the processor, memory, OS, and video card from the system. |
| MalwareAkira | Akira uses the |
| MalwareAmadey | Amadey has collected the computer name and OS version from a compromised machine. |
| MalwareAnchor | Anchor can determine the hostname and linux version on a compromised host. |
View all 355 software examples
| Used by | Procedure example |
|---|---|
| CampaignAnthropic AI-orchestrated Campaign | During the Anthropic AI-orchestrated Campaign, the adversary tasked Claude Code to query databases and systems in order to identify proprietary information, including system configurations and database types. |
| CampaignArcaneDoor | ArcaneDoor included collection of victim device configuration information. |
| CampaignCutting Edge | During Cutting Edge, threat actors used the ENUM4LINUX Perl script for discovery on Windows and Samba hosts. |
| CampaignFrankenstein | During Frankenstein, the threat actors used Empire to obtain the compromised machine's name. |
| CampaignFunnyDream | During FunnyDream, the threat actors used Systeminfo to collect information on targeted hosts. |
| CampaignJuicy Mix | During Juicy Mix, OilRig used a script to send the name of the compromised host via HTTP `POST` to register it with C2. |
| CampaignKV Botnet Activity | KV Botnet Activity includes use of native system tools, such as |
| CampaignLeviathan Australian Intrusions | Leviathan performed host enumeration and data gathering operations on victim machines during Leviathan Australian Intrusions. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.