Real-world descriptions of how a group, tool or campaign used a technique.
58 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1082 System Information Discovery |
GroupAPT38 | APT38 has attempted to get detailed information about a compromised host, including the operating system, version, patches, hotfixes, and service packs. |
| T1082 System Information Discovery |
GroupBlackByte | BlackByte used various system commands and tools to pull system information during operations. |
| T1082 System Information Discovery |
GroupSideCopy | SideCopy has identified the OS version of a compromised host. |
| T1082 System Information Discovery |
GroupAPT3 | APT3 has a tool that can obtain information about the local system. |
| T1082 System Information Discovery |
GroupMustard Tempest | Mustard Tempest has used implants to perform system reconnaissance on targeted systems. |
| T1082 System Information Discovery |
GroupKimsuky | Kimsuky has enumerated OS type, OS version, and other information using a script or the "systeminfo" command. Kimsuky has also obtained system information such as OS type, OS version, and system type through querying various Windows Management Instrumentation (WMI) classes including `Win32_OperatingSystem`. |
| T1082 System Information Discovery |
Groupadmin@338 | admin@338 actors used the following commands after exploiting a machine with LOWBALL malware to obtain information about the OS: |
| T1082 System Information Discovery |
GroupPatchwork | Patchwork collected the victim computer name, OS version, and architecture type and sent the information to its C2 server. |
| T1082 System Information Discovery |
GroupAPT41 | APT41 uses multiple built-in commands such as |
| T1082 System Information Discovery |
GroupAPT32 | APT32 has collected the OS version and computer name from victims. One of the group's backdoors can also query the Windows Registry to gather system information, and another macOS backdoor performs a fingerprint of the machine on its first connection to the C&C server. APT32 executed shellcode to identify the name of the infected host. |
| T1082 System Information Discovery |
GroupMuddyWater | MuddyWater has used malware that can collect the victim’s OS version and machine name. |
| T1082 System Information Discovery |
GroupGamaredon Group | A Gamaredon Group file stealer can gather the victim's computer name and drive serial numbers to send to a C2 server. |
| T1082 System Information Discovery |
GroupTeamTNT | TeamTNT has searched for system version, architecture, and hostname information. |
| T1082 System Information Discovery |
GroupFIN7 | FIN7 has used csvde.exe, which is a built-in Windows command line tool, to export system information. Additionally, WsTaskLoad has gathered system information, such as operating system and hostname. |
| T1082 System Information Discovery |
GroupSandworm Team | Sandworm Team used a backdoor to enumerate information about the infected system's operating system. |
| T1082 System Information Discovery |
GroupAPT18 | APT18 can collect system information from the victim’s machine. |
| T1082 System Information Discovery |
GroupCURIUM | CURIUM deploys information gathering tools focused on capturing IP configuration, running application, system information, and network connectivity information. |
| T1082 System Information Discovery |
GroupSidewinder | Sidewinder has used tools to collect the computer name, OS version, installed hotfixes, as well as information regarding the memory and processor on a compromised host. |
| T1082 System Information Discovery |
GroupMustang Panda | Mustang Panda has gathered system information using |
| T1082 System Information Discovery |
GroupZIRCONIUM | ZIRCONIUM has used a tool to capture the processor architecture of a compromised host in order to register it with C2. |
| T1082 System Information Discovery |
GroupRocke | Rocke has used uname -m to collect the name and information about the infected system's kernel. |
| T1082 System Information Discovery |
GroupScattered Spider | Scattered Spider has executed scripts to identify the underlying operating system to ensure it uses the correct installation package for malicious payloads. |
| T1082 System Information Discovery |
GroupContagious Interview | Contagious Interview has configured malicious webpages to identify the victim’s operating system by reviewing the details of the victims User-Agent of their browser. |
| T1082 System Information Discovery |
GroupTA2541 | TA2541 has collected system information prior to downloading malware on the targeted host. |
| T1082 System Information Discovery |
GroupAPT37 | APT37 collects the computer name, the BIOS model, and execution path. |
| T1082 System Information Discovery |
GroupMoses Staff | Moses Staff collected information about the infected host, including the machine names and OS architecture. |
| T1082 System Information Discovery |
GroupOilRig | OilRig has run |
| T1082 System Information Discovery |
GroupWindigo | Windigo has used a script to detect which Linux distribution and version is currently installed on the system. |
| T1082 System Information Discovery |
GroupHigaisa | Higaisa collected the system GUID and computer name. |
| T1082 System Information Discovery |
GroupTropic Trooper | Tropic Trooper has detected a target system’s OS version. |
| T1082 System Information Discovery |
GroupAquatic Panda | Aquatic Panda has used native OS commands to understand privilege levels and system details. |
| T1082 System Information Discovery |
GroupKe3chang | Ke3chang performs operating system information discovery using |
| T1082 System Information Discovery |
GroupBlue Mockingbird | Blue Mockingbird has collected hardware details for the victim's system, including CPU and memory information. |
| T1082 System Information Discovery |
GroupWinter Vivern | Winter Vivern script execution includes basic victim information gathering steps which are then transmitted to command and control servers. |
| T1082 System Information Discovery |
GroupTurla | Turla surveys a system upon check-in to discover operating system configuration details using the |
| T1082 System Information Discovery |
GroupStorm-0501 | Storm-0501 has leveraged native Windows tools and commands such as `systeminfo` and open-source tools including OSQuery and ossec-win32 to query details about the endpoint. |
| T1082 System Information Discovery |
GroupRedCurl | RedCurl has collected information about the target system, such as system information and list of network connections. |
| T1082 System Information Discovery |
GroupStealth Falcon | Stealth Falcon malware gathers system information via WMI, including the system directory, build number, serial number, version, manufacturer, model, and total physical memory. |
| T1082 System Information Discovery |
GroupMirrorFace | MirrorFace has employed malicious macros and native Windows tools such as csvde.exe, nltest.exe and quser.exe for discovery. |
| T1082 System Information Discovery |
GroupMedusa Group | Medusa Group has leveraged `cmd.exe` to identify system info `cmd.exe /c systeminfo`. |
| T1082 System Information Discovery |
GroupDarkhotel | Darkhotel has collected the hostname, OS version, service pack version, and the processor architecture from the victim’s machine. |
| T1082 System Information Discovery |
GroupWindshift | Windshift has used malware to identify the computer name of a compromised host. |
| T1082 System Information Discovery |
GroupMalteiro | Malteiro collects the machine information, system architecture, the OS version, computer name, and Windows product name. |
| T1082 System Information Discovery |
GroupAPT42 | APT42 has used malware, such as GHAMBAR and POWERPOST, to collect system information. |
| T1082 System Information Discovery |
GroupLazarus Group | Several Lazarus Group malware families collect information on the type and version of the victim OS, as well as the victim computer name and CPU information. |
| T1082 System Information Discovery |
GroupSowbug | Sowbug obtained OS version and hardware configuration from a victim. |
| T1082 System Information Discovery |
GroupWizard Spider | Wizard Spider has used Systeminfo and similar commands to acquire detailed configuration information of a victim's machine. Wizard Spider has also utilized the PowerShell cmdlet `Get-ADComputer` to collect DNS hostnames, last logon dates, and operating system information from Active Directory. |
| T1082 System Information Discovery |
GroupMoonstone Sleet | Moonstone Sleet has gathered information on victim systems. |
| T1082 System Information Discovery |
GroupInception | Inception has used a reconnaissance module to gather information about the operating system and hardware on the infected host. |
| T1082 System Information Discovery |
GroupVOID MANTICORE | VOID MANTICORE has gathered system information and disseminated it back to C2. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.