FORENSIA

ATT&CK · T1082

System Information Discovery

Tactics: discovery

About

An adversary may attempt to get detailed information about the operating system and hardware, including version, patches, hotfixes, service packs, and architecture. Adversaries may use this information to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions. This behavior is distinct from Local Storage Discovery which is an adversary's discovery of local drive, disks and/or volumes. Tools such as Systeminfo can be used to gather detailed system information. If running with privileged access, a breakdown of system data can be gathered through the <code>systemsetup</code> configuration tool on macOS. Adversaries may leverage a Network Device CLI on network devices to gather detailed system information (e.g. <code>show version</code>). On ESXi servers, threat actors may gather system information from various esxcli utilities, such as `system hostname get` and `system version get`. Infrastructure as a Service (IaaS) cloud providers such as AWS, GCP, and Azure allow access to instance and virtual machine information via APIs. Successful authenticated API calls can return data such as the operating system platform and status of a particular instance or the model view of a virtual machine. System Information Discovery combined with information gathered from other forms of discovery and reconnaissance can drive payload development and concealment.

Platforms: ESXi, IaaS, Linux, macOS, Network Devices, WindowsMITRE ATT&CK ↗

Used by actors

57 known groups

Software

353 malware/tools implement this

PlugXIxesheBISCUITDerusbiUroburosDyreBACKSPACEgh0st RATBUBBLEWRAPADVSTORESHELLCozyCarPinchDukeMiniDukeSslMMWinMMSys10DustySky4H RATMobileOrderEliseEmissaryMisdatMis-TypeS-TypeZLibKasidetBlackEnergyEpicBackdoor.OldreaTrojan.KaraganySysteminfoT9000dsquerycmdPrikormkaCrimsonPisloaderRemsecUnknown LoggerCORESHELLPowerDukeShamoonWinnti for WindowsStreamExChChesRTMMoonWindHALFBAKEDRedLeavesWINDSHIELDKOMPROGOSOUNDBITEXAgentOSXOSInfoFelismusReaverWingbirdVolgmerFALLCHILLFinFisherPOWRUNERDownPaperPupyPUNCHBUGGYNETWIRETURNEDUPJPINHydraqNaidPasamLinfoHAPPYWORKKARAEPOORAIMSHUTTERSPEEDSLOWDRIFTWINERACKPOWERSTATSNanHaiShuOrzZeroTMURKYTOPKwampirsGravityRATProxysvcBankshotROKRATRATANKBASynAckComnieBADCALLNavRATytyGold DragonKoadicZebrocyBrave PrinceRunningRATPLAINTEEVERMINInnaputRATInvisiMoleQuasarRATOopsIEKazuarTrickBotFELIXROOTBisonalRogueRobinKEYMARBLENDiskMonitorUPPERCUTMirageFoxjRATMore_eggsZeus PandaAgent TeslaRemcosDarkCometBadPatchMicropsiaOctopusAzorultOceanSaltCardinal RATzwShellCannonOSX_OCEANLOTUS.DNOKKIDenisFinal1stspyKONNIEmpireAstarothSpeakUpHOPLIGHTPoshC2Revenge RATStoneDrillFlawedAmmyyServHelperDridexnjRATUrsnifKeyBoyYAHOYAHHAWKBALLLightNeuronOSX/ShlayerMacheteFysbisZxShellBabySharkGRIFFONPoetRATHotCroissantRifdoorOkrumPowerShowerShimRatReporterLokibotRising SunMazeSHARPSTATSLoudMinerPonyCadelspyMetamorfoAria-bodyNetwalkerGet2SDBbotCARROTBATSYSCONTajMahalSkidmapAvengerBackConfigValakBundloreIcedIDCarberpBonadanKesselGoldenSpyREvilPipeMonAnchorFatDukeLiteDukeWellMessSoreFangBLINDINGCANGrandoreiroLuciferSLOTHFULMEDIABazarSparkSharpStageDropBookMoleNetEgregorPay2KeySUNBURSTDtrackEVILNUMExplosiveCaterpillar WebShellAppleJeusKerrdownPenquinShadowPadHildegardStuxnetIndustroyerSideTwistSombRATAppleSeedSodaMasterChaesGrimAgentEnvyScoutBoomBoxKobalosBADFLICKObliqueRATSpicyOmeletteTurianSMOKEDHAMQakBotMarkiRATBLUELIGHTXCSSETDiavolClamblingRCSessionSysUpdateThreatNeedleGelsemiumChrommmeKOCTOPUSWarzoneRATDarkWatchmanCharmPowerFerociousLitePowerLizarCyclops BlinkMeteorGreen LambertNeoichorSILENTTRINITYCaddyWiperHermeticWiperZxxZMilanMacMaSaint BotSharkKevinIceAppleAmadeyMongallAction RATAuTo StealerSquirrelwafflePingPullStrifeWaterSTARWHALEBumblebeemacOS.OSAMinerDEADEYEmetaMainMafaldaSVCReadyWoody RATDarkTortillaBlackCatBlack BastaRoyalRotaJakiroBADHATCHSardonicSnip3NinjaNKAbuseDarkGateLITTLELAMB.WOOLTEAMispaduSocGholishAkiraRaspberry RobinGootloaderLunarWebLunarMailPikabotNightdoorRaccoon StealerIMAPLoaderCuckoo StealerCovenantManjusakaDUSTTRAPLatrodectusSolarAcidPourSampleCheck5000MangoOilBoosterShrinkLockerBlackByte RansomwareMagicRATStrelaStealerBOLDMOVELightSpyLine DancerKapekaTroll StealerGomirLockBit 2.0StealBitLockBit 3.0XLoaderSagerunexRansomHubLumma StealerRIFLESPINEPUBLOADHavocSplatCloakTONESHELLRedLine StealerQilinMedusa RansomwareInvisibleFerretBeaverTailXORIndex LoaderHexEval LoaderSystemBCDiskpartShai-HuludGlassWormPureCrypterLODEINFOHiddenFaceSPAWNCHIMERANOOPLDRIronWindAshTagTsundere BotnetLAMEHUGRustyWaterLazyWiper

Corpus indicators tagged with this technique

7,592 indicators in the corpus carry T1082.

IndicatorTypeFamilySevSrc
cve-2020-22653cve852
cve-2025-7443cve851
cve-2018-8007cve851
cve-2020-17456cve851
cve-2021-25646cve851
cve-2025-34085cve851
cve-2025-11837cve852
cve-2024-1781cve851
cve-2014-2321cve851
cve-2021-4045cve851
cve-2025-34117cve851
cve-2013-7471cve851
cve-2026-0740cve851
cve-2025-12057cve851
cve-2021-27076cve851
cve-2013-3307cve852
cve-2016-15047cve854
cve-2025-34054cve854
cve-2016-5681cve852
cve-2022-47945cve851
cve-2026-3102cve853
cve-2023-44976cveransomware852
cve-2020-22658cve852
cve-2025-2492cve852
cve-2026-4368cveransomware851
cve-2017-18377cve851
cve-2021-29441cve851
cve-2026-1969cve851
cve-2026-3844cve851
cve-2025-7852cve851

Showing the top 30 by severity of 7,592.