Client Configurations

T1592.004

Sub-technique of T1592 Gather Victim Host Information.View on attack.mitre.org

About this technique

Adversaries may gather information about the victim's client configurations that can be used during targeting. Information about client configurations may include a variety of details and settings, including operating system/version, virtualization, architecture (ex: 32 or 64 bit), language, and/or time zone.

Adversaries may gather this information in various ways, such as direct collection actions via Active Scanning (ex: listening ports, server banners, user agent strings) or Phishing for Information. Adversaries may also compromise sites then include malicious content designed to collect host information from visitors. Information about the client configurations may also be exposed to adversaries via online or other accessible data sets (ex: job postings, network maps, assessment reports, resumes, or purchase invoices). Gathering this information may reveal opportunities for other forms of reconnaissance (ex: Search Open Websites/Domains or Search Open Technical Databases), establishing operational resources (ex: Develop Capabilities or Obtain Capabilities), and/or initial access (ex: Supply Chain Compromise or External Remote Services).

Detection rules4

Rules on DetectionCode tagged with T1592.004.

Sigma3

RuleLevelLog source
Linux Recon Indicatorshighlinux / process_creation
Access of Sudoers File Contentmediumlinux / process_creation
Print History File Contentsmediumlinux / process_creation

Splunk1

RuleTypeRiskData source
Windows WinPEAS PowerShell Script ExecutionTTPNULLPowershell Script Block Logging 4104

Groups1

Software0

None recorded.

Campaigns1

Procedure examples2

Groups1

Used byProcedure example
GroupHAFNIUM

HAFNIUM has interacted with Office 365 tenants to gather details regarding target's environments.

Campaigns1

Used byProcedure example
CampaignAnthropic AI-orchestrated Campaign

During the Anthropic AI-orchestrated Campaign, the adversary leveraged Claude Code to gather details of high-value systems to include databases and workflow orchestration platforms.

References1

  1. ATT ScanBox Open source
    Blasco, J. (2014, August 28). Scanbox: A Reconnaissance Framework Used with Watering Hole Attacks. Retrieved October 19, 2020.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.