MITRE ATT&CK technique
T1082 — System Information Discovery
Last fetched
T1082 (System Information Discovery) is a MITRE ATT&CK technique tracked in WhisperGraph, serving the Discovery tactic.
Description
An adversary may attempt to get detailed information about the operating system and hardware, including version, patches, hotfixes, service packs, and architecture. Adversaries may use this information to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions. This behavior is distinct from [Local Storage Discovery](https://attack.mitre.org/techniques/T1680) which is an adversary's discovery of local drive, disks and/or volumes. Tools such as [Systeminfo](https://attack.mitre.org/software/S0096) can be used to gather detailed system information. If running with privileged access, a breakdown of system data can be gathered through the <code>systemsetup</code> configuration tool on macOS. Adversaries may leverage a [Network Device CLI](https://attack.mitre.org/techniques/T1059/008) on network devices to gather detailed system information (e.g. <code>show version</code>).(Citation: US-CERT-TA18-106A) On ESXi servers, threat actors may gather system information from various esxcli utilities, such as `system hostname get` and `system version get`.(Citation: Crowdstrike Hypervisor Jackpotting Pt 2 2021)(Citation: Varonis) Infrastructure as a Service (IaaS) cloud providers such as AWS, GCP, and Azure allow access to instance and virtual machine information via APIs. Successful authenticated API calls can return data such as the operating system platform and status of a particular instance or the model view of a virtual machine.(Citation: Amazon Describe Instance)(Citation: Google Instances Resource)(Citation: Microsoft Virutal Machine API) [System Information Discovery](https://attack.mitre.org/techniques/T1082) combined with information gathered from other forms of discovery and reconnaissance can drive payload development and concealment.(Citation: OSX.FairyTale)(Citation: 20 macOS Common Tools and Techniques)
Tactics
Threat actors observed using this technique
- Blue Mockingbird
- Mustang Panda
- Mustard Tempest
- Play
- Stealth Falcon
- Contagious Interview
- Higaisa
- Sowbug
- APT3
- Scattered Spider
- HEXANE
- Gamaredon Group
- Inception
- Malteiro
- MirrorFace
- Ke3chang
- Medusa Group
- FIN13
- Storm-0501
- BlackByte
- ZIRCONIUM
- Wizard Spider
- ShinyHunters
- SideCopy
- CURIUM
- APT42
- APT41
- Moses Staff
- Turla
- MuddyWater
- APT38
- APT37
- Sandworm Team
- APT32
- Magic Hound
- Aquatic Panda
- Windigo
- VOID MANTICORE
- Rocke
- Kimsuky
- OilRig
- TeamTNT
- Tropic Trooper
- FIN7
- FIN8
- Daggerfly
- APT18
- APT19
- Sidewinder
- admin@338
- Darkhotel
- Winter Vivern
- Windshift
- Patchwork
- TA2541
- Moonstone Sleet
- RedCurl
- Lazarus Group
- WIZARD SPIDER
- MUSTANG PANDA
- Void Manticore
- DarkHotel
© The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.
Related pages
Pivot from T1082 into its tactic, related techniques and the actors that use it.
Queries
Resolves the segment to this technique or tactic.
MATCH (t:ATTACK_PATTERN {name: $id})
RETURN t.id AS id, t.name AS name, t.kind AS kind, t.description AS descriptionRun yourself →The tactic(s) this technique serves.
MATCH (t:ATTACK_PATTERN {name: $id})-[:USES_TACTIC]->(tac:ATTACK_PATTERN)
RETURN tac.id AS id, tac.name AS name
LIMIT 10Run yourself →This id's parent technique, if it is a sub-technique.
MATCH (p:ATTACK_PATTERN {name: $parentId})
RETURN p.id AS id, p.name AS name
LIMIT 1Run yourself →Sub-techniques of this technique, if any.
MATCH (c:ATTACK_PATTERN) WHERE c.id STARTS WITH $subPrefix
RETURN c.id AS id, c.name AS name
ORDER BY c.id
LIMIT 25Run yourself →Threat actors observed using this technique.
MATCH (a:ACTOR)-[:USES_TECHNIQUE]->(t:ATTACK_PATTERN {name: $id})
RETURN a.name AS name
LIMIT 100Run yourself →Or query Whisper from your own LLM workflow via the Whisper MCP server.