Real-world descriptions of how a group, tool or campaign used a technique.
355 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1082 System Information Discovery |
MalwareTrickBot | TrickBot gathers the OS version, machine name, CPU type, amount of RAM available, and UEFI/BIOS firmware information from the victim’s machine. |
| T1082 System Information Discovery |
MalwarePowerDuke | PowerDuke has commands to get information about the victim's name, build, version, serial number, and memory usage. |
| T1082 System Information Discovery |
MalwareBLINDINGCAN | BLINDINGCAN has collected from a victim machine the system name, processor information, and OS version. |
| T1082 System Information Discovery |
MalwareNinja | Ninja can obtain the computer name and information on the OS from targeted hosts. |
| T1082 System Information Discovery |
MalwarePikabot | Pikabot performs a variety of system checks and gathers system information, including commands such as |
| T1082 System Information Discovery |
MalwareRCSession | RCSession can gather system information from a compromised host. |
| T1082 System Information Discovery |
MalwareSpark | Spark can collect the hostname, keyboard layout, and language from the system. |
| T1082 System Information Discovery |
MalwareSynAck | SynAck gathers computer names, OS version info, and also checks installed keyboard layouts to estimate if it has been launched from a certain list of countries. |
| T1082 System Information Discovery |
MalwareBumblebee | Bumblebee can enumerate the OS version and domain on a targeted system. |
| T1082 System Information Discovery |
MalwareMURKYTOP | MURKYTOP has the capability to retrieve information about the OS. |
| T1082 System Information Discovery |
MalwareGRIFFON | GRIFFON has used a reconnaissance module that can be used to retrieve information about a victim's computer, including the resolution of the workstation . |
| T1082 System Information Discovery |
MalwareAmadey | Amadey has collected the computer name and OS version from a compromised machine. |
| T1082 System Information Discovery |
MalwareProxysvc | Proxysvc collects the OS version, country name, MAC address, computer name, and physical memory statistics. |
| T1082 System Information Discovery |
MalwareOrz | Orz can gather the victim OS version and whether it is 64 or 32 bit. |
| T1082 System Information Discovery |
MalwareNOKKI | NOKKI can gather information on the operating system on the victim’s machine. |
| T1082 System Information Discovery |
Malwareyty | yty gathers the computer name, CPU information, Microsoft Windows version, and runs the command |
| T1082 System Information Discovery |
MalwareBackdoor.Oldrea | Backdoor.Oldrea collects information about the OS and computer name. |
| T1082 System Information Discovery |
MalwareStuxnet | Stuxnet collects system information including computer and domain names, OS version, and S7P paths. |
| T1082 System Information Discovery |
MalwareIronWind | IronWind can capture the OS version and computer name of the compromised host. |
| T1082 System Information Discovery |
MalwareRotaJakiro | RotaJakiro executes a set of commands to collect device information, including `uname`. Another example is the `cat /etc/*release | uniq` command used to collect the current OS distribution. |
| T1082 System Information Discovery |
MalwareGet2 | Get2 has the ability to identify the computer name and Windows version of an infected host. |
| T1082 System Information Discovery |
MalwarePOWRUNER | POWRUNER may collect information about the system by running |
| T1082 System Information Discovery |
MalwareSharpStage | SharpStage has checked the system settings to see if Arabic is the configured language. |
| T1082 System Information Discovery |
MalwareSardonic | Sardonic has the ability to collect the computer name, and CPU manufacturer name from a compromised machine. Sardonic also has the ability to execute the `ver` and `systeminfo` commands. |
| T1082 System Information Discovery |
MalwareHALFBAKED | HALFBAKED can obtain information about the OS, processor, and BIOS. |
| T1082 System Information Discovery |
MalwareMisdat | The initial beacon packet for Misdat contains the operating system version of the victim. |
| T1082 System Information Discovery |
MalwareEmissary | Emissary has the capability to execute ver and systeminfo commands. |
| T1082 System Information Discovery |
MalwareKEYMARBLE | KEYMARBLE has the capability to collect the computer name, language settings, the OS version, CPU information, and time elapsed since system start. |
| T1082 System Information Discovery |
MalwareBUBBLEWRAP | BUBBLEWRAP collects system information, including the operating system version and hostname. |
| T1082 System Information Discovery |
MalwareHAWKBALL | HAWKBALL can collect the OS version, architecture information, and computer name. |
| T1082 System Information Discovery |
MalwareUrsnif | Ursnif has used Systeminfo to gather system information. |
| T1082 System Information Discovery |
MalwareThreatNeedle | ThreatNeedle can collect system profile information from a compromised host. |
| T1082 System Information Discovery |
MalwareRansomHub | RansomHub can retrieve information about virtual machines. |
| T1082 System Information Discovery |
MalwareZLib | ZLib has the ability to enumerate system information. |
| T1082 System Information Discovery |
MalwareRedLeaves | RedLeaves can gather extended system information including the hostname, OS version number, platform, memory information, time elapsed since system startup, and CPU information. |
| T1082 System Information Discovery |
MalwareTsundere Botnet | Tsundere Botnet has collected the machine’s MAC address, total memory, GPU information and other system information. |
| T1082 System Information Discovery |
MalwareLITTLELAMB.WOOLTEA | LITTLELAMB.WOOLTEA can check the type of Ivanti VPN device it is running on by executing `first_run()` to identify the first four bytes of the motherboard serial number. |
| T1082 System Information Discovery |
MalwareFelismus | Felismus collects the system information, including hostname and OS version, and sends it to the C2 server. |
| T1082 System Information Discovery |
MalwareZeus Panda | Zeus Panda collects the OS version, system architecture, computer name, product ID, install date, and information on the keyboard mapping to determine the language used on the system. |
| T1082 System Information Discovery |
MalwareHavoc | Havoc can gather system information including hostname, domain, and OS details. |
| T1082 System Information Discovery |
MalwareCARROTBAT | CARROTBAT has the ability to determine the operating system of the compromised host and whether Windows is being run with x86 or x64 architecture. |
| T1082 System Information Discovery |
MalwareGravityRAT | GravityRAT collects the MAC address, computer name, and CPU information. |
| T1082 System Information Discovery |
MalwareInvisibleFerret | InvisibleFerret has collected OS type, hostname and system version through the "pay" module. InvisibleFerret has also queried the victim device using Python scripts to obtain the User and Hostname. |
| T1082 System Information Discovery |
MalwareBankshot | Bankshot gathers system information, network addresses, and the operation system version. |
| T1082 System Information Discovery |
MalwareHAPPYWORK | can collect system information, including computer name, system manufacturer, IsDebuggerPresent state, and execution path. |
| T1082 System Information Discovery |
MalwarePLAINTEE | PLAINTEE collects general system enumeration data about the infected machine and checks the OS version. |
| T1082 System Information Discovery |
MalwarePony | Pony has collected the Service Pack, language, and region information to send to the C2. |
| T1082 System Information Discovery |
MalwareWinMM | WinMM collects the system name, OS version including service pack, and system install date and sends the information to the C2 server. |
| T1082 System Information Discovery |
MalwareTONESHELL | TONESHELL has the ability to retrieve the name of the infected machine. |
| T1082 System Information Discovery |
MalwareKasidet | Kasidet has the ability to obtain a victim's system name and operating system version. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.