Cross-source coverage
T1082 / ATT&CK
System Information Discovery
212 rules · 208 families across 8 sources.
6 atomic-IOC hidden · include
Showing deprecated rules · back to the default
From MITRE ATT&CK 19.2
An adversary may attempt to get detailed information about the operating system and hardware, including version, patches, hotfixes, service packs, and architecture. Adversaries may use this information to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions. This behavior is distinct from Local Storage Discovery which is an adversary's discovery of local drive, disks and/or volumes.
Tools such as Systeminfo can be used to gather detailed system information. If running with privileged access, a breakdown of system data can be gathered through the systemsetup configuration tool on macOS. Adversaries may leverage a Network Device CLI on network devices to gather detailed system information (e.g. show version). On ESXi servers, threat actors may gather system information from various esxcli utilities, such as system hostname get and system version get.
Infrastructure as a Service (IaaS) cloud providers such as AWS, GCP, and Azure allow access to instance and virtual machine information via APIs. Successful authenticated API calls can return data such as the operating system platform and status of a particular instance or the model view of a virtual machine.
System Information Discovery combined with information gathered from other forms of discovery and reconnaissance can drive payload development and concealment.
- Tactics
- Discovery
- Platforms
- ESXi · IaaS · Linux · macOS · Network Devices · Windows
- Telemetry
-
WinEventLog:SecurityWinEventLog:PowerShellWinEventLog:Sysmonauditd:SYSCALLmacos:unifiedlogesxi:vmkernelAWS:CloudTrailnetworkdevice:syslog
How MITRE says to detect it DET0525
System Discovery via Native and Remote Utilities
Windows Analytic 1452
Detection of processes executing system environment inspection operations followed by access to OS configuration APIs or registry locations that expose OS version, architecture, patch level, or hardware characteristics. Defenders observe process execution retrieving system configuration metadata immediately after process startup.
WinEventLog:SecurityEventCode=4688WinEventLog:PowerShellEventCode=4103, 4104, 4105, 4106WinEventLog:SysmonEventCode=1WinEventLog:SysmonEventCode=13, 14
Linux Analytic 1453
Execution of system enumeration commands such as `uname`, `df`, `uptime`, `hostname`, `lscpu`, and `cat /etc/os-release` through local terminal or scripts.
auditd:SYSCALLexecve
macOS Analytic 1454
Execution of system info utilities like `systemsetup`, `sw_vers`, `uname`, or `sysctl` by terminal or scripted processes.
macos:unifiedloglog show --predicate 'process == <utility>'
ESXi Analytic 1455
Execution of `esxcli system hostname get`, `esxcli system version get`, or `esxcli hardware` commands through SSH or local shell.
esxi:vmkernel/var/log/vmkernel.log
IaaS Analytic 1456
Use of cloud API calls (e.g., AWS EC2 DescribeInstances, Azure VM Inventory) to enumerate system configurations across assets.
AWS:CloudTrailDescribeInstances, GetConsoleOutput, DescribeImages
Network Devices Analytic 1457
Execution of `show version`, `show hardware`, or `show system` commands through CLI via SSH or console.
networkdevice:syslogPrivilege-level command execution
Emerging Threats Open
65 rules · 64 families+ 55 more from Emerging Threats Open → showing the 10 highest-severity
elastic/detection-rules
37 rules| Detection | Severity | Format |
|---|---|---|
| Entra ID Sign-in BloodHound Suite User-Agent Detected | High | Elastic TOML |
| Entra ID Sign-in TeamFiltration User-Agent Detected | High | Elastic TOML |
| Potential Meterpreter Reverse Shell | High | Elastic TOML |
| Suspicious React Server Child Process | High | Elastic TOML |
| Virtual Machine Fingerprinting | High | Elastic TOML |
| Wireless Credential Dumping using Netsh Command | High | Elastic TOML |
| Discovery Command Output Written to Suspicious File | Medium | Elastic TOML |
| Hping Process Activity | Medium | Elastic TOML |
| Kernel Seeking Activity | Medium | Elastic TOML |
| Kernel Unpacking Activity | Medium | Elastic TOML |
+ 27 more from elastic/detection-rules → showing the 10 highest-severity
socfortress/Wazuh-Rules
37 rules · 34 families| Detection | Severity | Format |
|---|---|---|
| Detects System Information Discovery commands. 4 variants | High | Wazuh XML |
| Detects System Information Discovery commands. 4 variants | High | Wazuh XML |
| Detects System Information Discovery commands. 4 variants | High | Wazuh XML |
| Detects System Information Discovery commands. 4 variants | High | Wazuh XML |
| FreeBSD: Kernel module listing (kldstat) - potential virtualization check | High | Wazuh XML |
| Potential VM discovery: grep for virtualization kernel modules | High | Wazuh XML |
| Sysmon - Event 1: Process creation · Execution of hostname (T1082) | High | Wazuh XML |
| Sysmon - Event 1: Process creation · Execution of set command (T1082) | High | Wazuh XML |
| Sysmon - Event 1: Process creation · Execution of systeminfo (T1082) | High | Wazuh XML |
| Sysmon - Event 1: Process creation · Execution of ver command (T1082) | High | Wazuh XML |
+ 27 more from socfortress/Wazuh-Rules → showing the 10 highest-severity
SigmaHQ/sigma
33 rules| Detection | Severity | Format |
|---|---|---|
| HackTool - PCHunter Execution | High | Sigma |
| HackTool - winPEAS Execution | High | Sigma |
| HackTool - WinPwn Execution | High | Sigma |
| HackTool - WinPwn Execution - ScriptBlock | High | Sigma |
| Network Reconnaissance Activity | High | Sigma |
| Potential GobRAT File Discovery Via Grep | High | Sigma |
| Suspicious Kernel Dump Using Dtrace | High | Sigma |
| Bitbucket User Details Export Attempt Detected | Medium | Sigma |
| Bitbucket User Permissions Export Attempt | Medium | Sigma |
| Potential Product Class Reconnaissance Via Wmic.EXE | Medium | Sigma |
+ 23 more from SigmaHQ/sigma → showing the 10 highest-severity
splunk/security_content
18 rules| Detection | Severity | Format |
|---|---|---|
| Cisco ASA - Reconnaissance Command Activity | Undefined | SPL |
| Cisco IOS XE Reconnaissance Command Activity | Undefined | SPL |
| Detect attackers scanning for vulnerable JBoss servers | Undefined | SPL |
| ESXi System Information Discovery | Undefined | SPL |
| Linux Auditd Kernel Module Enumeration | Undefined | SPL |
| Linux Kernel Module Enumeration | Undefined | SPL |
| System Information Discovery Detection | Undefined | SPL |
| Web Servers Executing Suspicious Processes | Undefined | SPL |
| Windows Information Discovery Fsutil | Undefined | SPL |
| Windows Post Exploitation Risk Behavior | Undefined | SPL |
+ 8 more from splunk/security_content → showing the 10 highest-severity
elastic/protections-artifacts
9 rules| Detection | Severity | Format |
|---|---|---|
| Domain Computers Enumeration via LDAP Search | Undefined | Elastic TOML |
| Initial Access via macOS Installer Package | Undefined | Elastic TOML |
| Kerberos Config File Accessed by Osascript | Undefined | Elastic TOML |
| Multi-Value Secret Searching via Find | Undefined | Elastic TOML |
| Multi-Value Secret Searching via Grep | Undefined | Elastic TOML |
| Potential Virtual Machine Fingerprinting via VMDetect | Undefined | Elastic TOML |
| System Reconnaissance from Unsigned Parent Followed by Network Connection | Undefined | Elastic TOML |
| User TCC DB Access by Osascript | Undefined | Elastic TOML |
| User TCC DB Access by Unsigned or Untrusted Process | Undefined | Elastic TOML |
chronicle/detection-rules
7 rules| Detection | Severity | Format |
|---|---|---|
| sap_gateway_ufo_table_access | High | YARA-L |
| hacktool_winpeas_execution_patterns | Medium | YARA-L |
| recon_environment_enumeration_system_cisa_report | Low | YARA-L |
| hostdomain_enumeration_with_wmic | Undefined | YARA-L |
| netwire_rat_detection_via_wscript | Undefined | YARA-L |
| system_information_gathering_via_wmicexe | Undefined | YARA-L |
| ursnif_trojan_detection_cmd_obfuscation | Undefined | YARA-L |
Wazuh Core Ruleset
6 rules| Detection | Severity | Format |
|---|---|---|
| System information discovery activity detected | Medium | Wazuh XML |
| WMI query for System Information Discovery. | Medium | Wazuh XML |
| Powershell executed "GetComputerNameEx". Possible system configuration discovery | Low | Wazuh XML |
| Powershell queried Win32_BIOS. Possible sandbox detection activity | Low | Wazuh XML |
| Powershell script executed "ConvertSidToStringSid" API. Possible domain SID enumeration | Low | Wazuh XML |
| Powershell script querying system environment variables | Low | Wazuh XML |