T1082 System Information Discovery — ATT&CK Technique
An adversary may attempt to get detailed information about the operating system and hardware, including version, patches, hotfixes, service packs, and architecture. Adversaries may use this information to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions. This behavior is distinct from Local Storage Discovery which is an adversary's discovery of local drive, disks and/or volumes. Tools such as Systeminfo can be used to gather detailed system information. If running with privileged access, a breakdown of system data can be gathered through the systemsetup configuration tool on macOS. Adversaries may leverage a Network Device CLI on network devices to gather detailed system information (e.g. show version). On ESXi servers, threat actors may gather system information from various esxcli utilities, such as `system hostname get` and `system version get`. Infrastructure as a Service (IaaS) cloud providers such as AWS, GCP, and Azure allow access to instance and virtual machine information via APIs. Successful authenticated API calls can return data such as the operating system platform and status of a particular instance or the model view of a virtual machine. System Information Discovery combined with information gathered from other forms of discovery and reconnaissance can drive payload development and concealment.
Detection coverage (50)
- System Information Discovery informational
- CMD Shell Output Redirect low
- System Information Discovery Via Wmic.EXE low
- Bitbucket User Permissions Export Attempt medium
- Bitbucket User Details Export Attempt Detected medium
- System Information Discovery Via Sysctl - MacOS medium
- System Information Discovery Using System_Profiler medium
- System and Hardware Information Discovery informational
- System Info Discovery via Sysinfo Syscall low
- System Information Discovery - Auditd low
- Potential GobRAT File Discovery Via Grep high
- Container Residence Discovery Via Proc Virtual FS low
- Docker Container Discovery Via Dockerenv Listing low
- Potential Container Discovery Via Inodes Listing low
- System Information Discovery Using sw_vers medium
- Cisco Discovery low
- PUA - System Informer Execution medium
- OS Architecture Discovery Via Grep low
- Suspicious Query of MachineGUID low
- System Information Discovery Using Ioreg medium
- HackTool - WinPwn Execution - ScriptBlock high
- System Information Discovery via Registry Queries low
- Suspicious Kernel Dump Using Dtrace high
- HackTool - PCHunter Execution high
- HackTool - winPEAS Execution high
- HackTool - WinPwn Execution high
- Suspicious Execution of Hostname low
- Network Reconnaissance Activity high
- Potential Suspicious Activity Using SeCEdit medium
- Suspicious Execution of Systeminfo low
- Potential Product Class Reconnaissance Via Wmic.EXE medium
- System Disk And Volume Reconnaissance Via Wmic.EXE medium
- Uncommon System Information Discovery Via Wmic.EXE medium
- Cisco ASA - Reconnaissance Command Activity
- Cisco IOS XE Reconnaissance Command Activity
- ESXi System Information Discovery
- Linux Auditd Kernel Module Enumeration
- Linux Kernel Module Enumeration
- System Information Discovery Detection
- Web Servers Executing Suspicious Processes
- Windows Information Discovery Fsutil
- Windows Post Exploitation Risk Behavior
- Windows PowerShell Invoke-RestMethod IP Information Collection
- Windows PsTools Recon Usage
- Windows WinPEAS PowerShell Script Execution
- Windows Wmic CPU Discovery
- Windows Wmic Network Discovery
- Windows Wmic DiskDrive Discovery
- Windows Wmic Memory Chip Discovery
- Windows Wmic Systeminfo Discovery
Malware using this technique
- SideTwist
- Final1stspy
- Gomir
- PoetRAT
- Dyre
- LockBit 2.0
- Turian
- BeaverTail
- Zeus Panda
- Mafalda
- IronWind
- CaddyWiper
- Mongall
- Solar
- Brave Prince
- GrimAgent
- SocGholish
- FlawedAmmyy
- Dtrack
- Squirrelwaffle
- FinFisher
- WinMM
- Shark
- SynAck
- Caterpillar WebShell
- LODEINFO
- SpicyOmelette
- Hydraq
- Orz
- LightNeuron
- njRAT
- DarkTortilla
- NETWIRE
- NavRAT
- RogueRobin
- StealBit
- gh0st RAT
- Bisonal
- SOUNDBITE
- Chaes
- Naid
- Cardinal RAT
- SHUTTERSPEED
- SharpStage
- InvisibleFerret
- ShrinkLocker
- Rifdoor
- Egregor
- CARROTBAT
- Remsec
Threat actors using this technique
- Mustard Tempest
- Windigo
- BlackByte
- OilRig
- ZIRCONIUM
- APT41
- Blue Mockingbird
- HEXANE
- Darkhotel
- TA2541
- FIN13
- Rocke
- Gamaredon Group
- Sowbug
- Conti
- Turla
- APT37
- APT32
- Inception
- Lazarus Group
- Moses Staff
- Higaisa
- CURIUM
- Malteiro
- RedCurl
- APT38
- Mustang Panda
- Void Manticore
- FIN7
- Kimsuky
- MuddyWater
- TeamTNT
- Scattered Spider
- Patchwork
- APT3
- Sidewinder
- APT35
- Daggerfly
- MirrorFace
- Play Ransomware
- Storm-0501
- Contagious Interview
- APT42
- SideCopy
- Windshift
- admin@338
- FIN8
- Medusa Ransomware
- APT19
- APT18