Cross-source coverage

T1082 / ATT&CK

System Information Discovery

212 rules · 208 families across 8 sources.

6 atomic-IOC hidden · include

Showing deprecated rules · back to the default

From MITRE ATT&CK 19.2

An adversary may attempt to get detailed information about the operating system and hardware, including version, patches, hotfixes, service packs, and architecture. Adversaries may use this information to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions. This behavior is distinct from Local Storage Discovery which is an adversary's discovery of local drive, disks and/or volumes.

Tools such as Systeminfo can be used to gather detailed system information. If running with privileged access, a breakdown of system data can be gathered through the systemsetup configuration tool on macOS. Adversaries may leverage a Network Device CLI on network devices to gather detailed system information (e.g. show version). On ESXi servers, threat actors may gather system information from various esxcli utilities, such as system hostname get and system version get.

Infrastructure as a Service (IaaS) cloud providers such as AWS, GCP, and Azure allow access to instance and virtual machine information via APIs. Successful authenticated API calls can return data such as the operating system platform and status of a particular instance or the model view of a virtual machine.

System Information Discovery combined with information gathered from other forms of discovery and reconnaissance can drive payload development and concealment.

Tactics
Discovery
Platforms
ESXi · IaaS · Linux · macOS · Network Devices · Windows
Telemetry
WinEventLog:SecurityWinEventLog:PowerShellWinEventLog:Sysmonauditd:SYSCALLmacos:unifiedlogesxi:vmkernelAWS:CloudTrailnetworkdevice:syslog

How MITRE says to detect it DET0525

System Discovery via Native and Remote Utilities

Windows Analytic 1452

Detection of processes executing system environment inspection operations followed by access to OS configuration APIs or registry locations that expose OS version, architecture, patch level, or hardware characteristics. Defenders observe process execution retrieving system configuration metadata immediately after process startup.

  • WinEventLog:Security EventCode=4688
  • WinEventLog:PowerShell EventCode=4103, 4104, 4105, 4106
  • WinEventLog:Sysmon EventCode=1
  • WinEventLog:Sysmon EventCode=13, 14

Linux Analytic 1453

Execution of system enumeration commands such as `uname`, `df`, `uptime`, `hostname`, `lscpu`, and `cat /etc/os-release` through local terminal or scripts.

  • auditd:SYSCALL execve

macOS Analytic 1454

Execution of system info utilities like `systemsetup`, `sw_vers`, `uname`, or `sysctl` by terminal or scripted processes.

  • macos:unifiedlog log show --predicate 'process == <utility>'

ESXi Analytic 1455

Execution of `esxcli system hostname get`, `esxcli system version get`, or `esxcli hardware` commands through SSH or local shell.

  • esxi:vmkernel /var/log/vmkernel.log

IaaS Analytic 1456

Use of cloud API calls (e.g., AWS EC2 DescribeInstances, Azure VM Inventory) to enumerate system configurations across assets.

  • AWS:CloudTrail DescribeInstances, GetConsoleOutput, DescribeImages

Network Devices Analytic 1457

Execution of `show version`, `show hardware`, or `show system` commands through CLI via SSH or console.

  • networkdevice:syslog Privilege-level command execution

Emerging Threats Open

65 rules · 64 families
Detection Severity Format
ET EXPLOIT Citrix ADC and NetScaler Gateway Information Disclosure - Successful Response (CVE-2023-4966) Critical Suricata
ET ACTIVEX Microsoft XML Core Services DTD Cross Domain Information Disclosure clsid High Suricata
ET DELETED DLSw Information Disclosure CVE-2014-7992 High Suricata
ET DELETED Microsoft XML Core Services DTD Cross Domain Information Disclosure object High Suricata
ET DELETED Possible Internet Explorer VBscript failure to handle error case information disclosure CVE-2014-6332 High Suricata
ET DELETED Possible Internet Explorer VBscript failure to handle error case information disclosure CVE-2014-6332 Common Construct High Suricata
ET DELETED Possible Internet Explorer VBscript failure to handle error case information disclosure CVE-2014-6332 Common Construct Hex Encode High Suricata
ET EXPLOIT Cisco Data Center Network Manager Information Disclosure Inbound High Suricata
ET EXPLOIT Citrix ADC and NetScaler Gateway Information Disclosure Attempt (CVE-2023-4966) 2 variants High Suricata
ET EXPLOIT Citrix ADC and NetScaler Gateway Information Disclosure Attempt (CVE-2023-4966) 2 variants High Suricata

+ 55 more from Emerging Threats Open → showing the 10 highest-severity

elastic/detection-rules

37 rules
Detection Severity Format
Entra ID Sign-in BloodHound Suite User-Agent Detected High Elastic TOML
Entra ID Sign-in TeamFiltration User-Agent Detected High Elastic TOML
Potential Meterpreter Reverse Shell High Elastic TOML
Suspicious React Server Child Process High Elastic TOML
Virtual Machine Fingerprinting High Elastic TOML
Wireless Credential Dumping using Netsh Command High Elastic TOML
Discovery Command Output Written to Suspicious File Medium Elastic TOML
Hping Process Activity Medium Elastic TOML
Kernel Seeking Activity Medium Elastic TOML
Kernel Unpacking Activity Medium Elastic TOML

+ 27 more from elastic/detection-rules → showing the 10 highest-severity

socfortress/Wazuh-Rules

37 rules · 34 families
Detection Severity Format
Detects System Information Discovery commands. 4 variants High Wazuh XML
Detects System Information Discovery commands. 4 variants High Wazuh XML
Detects System Information Discovery commands. 4 variants High Wazuh XML
Detects System Information Discovery commands. 4 variants High Wazuh XML
FreeBSD: Kernel module listing (kldstat) - potential virtualization check High Wazuh XML
Potential VM discovery: grep for virtualization kernel modules High Wazuh XML
Sysmon - Event 1: Process creation · Execution of hostname (T1082) High Wazuh XML
Sysmon - Event 1: Process creation · Execution of set command (T1082) High Wazuh XML
Sysmon - Event 1: Process creation · Execution of systeminfo (T1082) High Wazuh XML
Sysmon - Event 1: Process creation · Execution of ver command (T1082) High Wazuh XML

+ 27 more from socfortress/Wazuh-Rules → showing the 10 highest-severity

SigmaHQ/sigma

33 rules
Detection Severity Format
HackTool - PCHunter Execution High Sigma
HackTool - winPEAS Execution High Sigma
HackTool - WinPwn Execution High Sigma
HackTool - WinPwn Execution - ScriptBlock High Sigma
Network Reconnaissance Activity High Sigma
Potential GobRAT File Discovery Via Grep High Sigma
Suspicious Kernel Dump Using Dtrace High Sigma
Bitbucket User Details Export Attempt Detected Medium Sigma
Bitbucket User Permissions Export Attempt Medium Sigma
Potential Product Class Reconnaissance Via Wmic.EXE Medium Sigma

+ 23 more from SigmaHQ/sigma → showing the 10 highest-severity

splunk/security_content

18 rules
Detection Severity Format
Cisco ASA - Reconnaissance Command Activity Undefined SPL
Cisco IOS XE Reconnaissance Command Activity Undefined SPL
Detect attackers scanning for vulnerable JBoss servers Undefined SPL
ESXi System Information Discovery Undefined SPL
Linux Auditd Kernel Module Enumeration Undefined SPL
Linux Kernel Module Enumeration Undefined SPL
System Information Discovery Detection Undefined SPL
Web Servers Executing Suspicious Processes Undefined SPL
Windows Information Discovery Fsutil Undefined SPL
Windows Post Exploitation Risk Behavior Undefined SPL

+ 8 more from splunk/security_content → showing the 10 highest-severity

elastic/protections-artifacts

9 rules
Detection Severity Format
Domain Computers Enumeration via LDAP Search Undefined Elastic TOML
Initial Access via macOS Installer Package Undefined Elastic TOML
Kerberos Config File Accessed by Osascript Undefined Elastic TOML
Multi-Value Secret Searching via Find Undefined Elastic TOML
Multi-Value Secret Searching via Grep Undefined Elastic TOML
Potential Virtual Machine Fingerprinting via VMDetect Undefined Elastic TOML
System Reconnaissance from Unsigned Parent Followed by Network Connection Undefined Elastic TOML
User TCC DB Access by Osascript Undefined Elastic TOML
User TCC DB Access by Unsigned or Untrusted Process Undefined Elastic TOML

chronicle/detection-rules

7 rules
Detection Severity Format
sap_gateway_ufo_table_access High YARA-L
hacktool_winpeas_execution_patterns Medium YARA-L
recon_environment_enumeration_system_cisa_report Low YARA-L
hostdomain_enumeration_with_wmic Undefined YARA-L
netwire_rat_detection_via_wscript Undefined YARA-L
system_information_gathering_via_wmicexe Undefined YARA-L
ursnif_trojan_detection_cmd_obfuscation Undefined YARA-L

Wazuh Core Ruleset

6 rules
Detection Severity Format
System information discovery activity detected Medium Wazuh XML
WMI query for System Information Discovery. Medium Wazuh XML
Powershell executed "GetComputerNameEx". Possible system configuration discovery Low Wazuh XML
Powershell queried Win32_BIOS. Possible sandbox detection activity Low Wazuh XML
Powershell script executed "ConvertSidToStringSid" API. Possible domain SID enumeration Low Wazuh XML
Powershell script querying system environment variables Low Wazuh XML

Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.