Clankerusecase
MITRE ATT&CK detection coverage
← Back to main site
Home/ MITRE Matrix/ Discovery/ T1082

T1082System Information Discovery

T1082 — System Information Discovery is a MITRE ATT&CK technique in the Discovery tactic. Clankerusecase tracks 20 detection use cases covering it and 9 threat-intel articles citing it.

Discovery
View on the matrix → Filter Detection Library MITRE official spec ↗
20Use cases
9Articles
0Sub-techniques
1Tactic

Use cases covering this technique (20)

Cisco ASA - Reconnaissance Command Activity ESCU actions · hunting P Cisco IOS XE Reconnaissance Command Activity ESCU actions · hunting P ESXi System Information Discovery ESCU actions · alerting P Linux Auditd Kernel Module Enumeration ESCU actions · hunting P Linux Kernel Module Enumeration ESCU actions · hunting P System Information Discovery Detection ESCU actions · alerting P Web Servers Executing Suspicious Processes ESCU actions · alerting P Windows Information Discovery Fsutil ESCU actions · hunting P Windows Post Exploitation Risk Behavior ESCU actions · alerting P Windows PowerShell Invoke-RestMethod IP Information Collection ESCU actions · hunting P Windows PsTools Recon Usage ESCU actions · hunting P Windows WinPEAS PowerShell Script Execution ESCU actions · alerting P Windows Wmic CPU Discovery ESCU actions · hunting P Windows Wmic DiskDrive Discovery ESCU actions · hunting P Windows Wmic Memory Chip Discovery ESCU actions · hunting P Windows Wmic Network Discovery ESCU actions · hunting P Windows Wmic Systeminfo Discovery ESCU actions · hunting P Detect attackers scanning for vulnerable JBoss servers ESCU actions · alerting P [LLM] Outbound recon callback from Yamcs host (curl/shell child of JVM to public IP) Bespoke c2 · alerting DSPCS [LLM] Python process spawning shell with TeamPCP recon chain (hostname; whoami; uname; ip addr fallback) Bespoke actions · alerting DSΣPDDCS

Articles citing this technique (9)