System Information Discovery T1082

Tactic: Discovery

An adversary may attempt to get detailed information about the operating system and hardware, including version, patches, hotfixes, service packs, and architecture. Adversaries may use this information to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions. This behavior is distinct from Local Storage Discovery which is an adversary's discovery of local drive, disks and/or volumes.

Events covered

20 catalog events are tagged with this technique by at least one rule.

Authoring guide

These 167 rules share fields, values, and exclusions.

Fields filtered most (105 distinct)

These fields appear most often in rule filters.

FieldRulesHowSample values
CommandLine58contains 37, regex_match 18, ends_with 6, eq 3, in 2, wildcard 2, is_not_null 1(?i)((tracert)|(query)|(net\s+((localgroup)|(group)|(conf..., (?i)(\s+|^)(systeminfo|reg\s+query|hostname|set)(\.exe)?(\s+|$), (?i)\s(os|logicaldisk|share|cpu|memorychip|useraccount|ni..., (?i)((netstat)|(netsh)|(schtasks)|(tasklist)|(driverquery..., (?i)((whoami)|(dir)|(hostname)|(hostname)|(systeminfo)|(i...
process_name56eq 32, in 20, regex_match 9, starts_with 3, contains 1, wildcard 1bash, wmic.exe, arp.exe, awk, busybox
EventType39eq 21, in 17, contains 1, wildcard 1exec, exec_event, ProcessRollup2, open, opened-file
host.os.type38eq 36, in 2
event.type36eq 36start, change
Image32ends_with 25, is_not_null 3, starts_with 3, wildcard 3, eq 1, regex_match 1\wmic.exe, /boot/, /cat, /dev/shm/, /grep
EventID26eq 264688, 1, 4104, 4103, 4799
process.args24eq 14, in 9, starts_with 8, wildcard 6, contains 3-c, */bin/*sh*, */bin/base64*-d*, */bin/chmod +x*, */bin/curl*.amazonaws.com*
OriginalFileName20eq 19, in 1wmic.exe, cmd.exe, fsutil.exe, net.exe, net1.exe
DataSource13eq 13ABAP_DUMPS, CLOUD_FOUNDRY_LOGS, DBACOCKPIT, HANA_AUDIT_TRAIL, INTERNAL
event.category12eq 12process, file, network
TargetFilename11eq 6, wildcard 4, starts_with 2, in 1/users/*/library/application support/com.apple.tcc/tcc.db, /*/.*, /etc/krb5.conf, /etc/machine-id, /etc/modprobe.conf
parent_process_name11in 4, eq 3, regex_match 3, is_not_null 1, starts_with 1(?i)(powershell|pwsh)\.exe, bash, (?i)(powershell\.exe)|(cmd\.exe), acrobat.exe, acrord32.exe
Type8eq 8
RecommendationDisplayName7ne 6, eq 1Activity log should be retained for at least one year

Top indicator values (1428 distinct)

These values appear most often in rule predicates.

FieldKindValueRules (here)Corpus reach
event.typeeq
start
361078
EventTypein
exec
16201
EventTypein
exec_event
13149
EventTypein
start
13163
EventTypein
ProcessRollup2
10117
EventTypein
process_started
983
EventTypein
executed
898
EventTypeeq
exec
13576
EventTypeeq
open
552
process_nameeq
wmic.exe
1066
process_nameeq
cmd.exe
6121
process_nameeq
hostname.exe
57
process_nameeq
nbtstat.exe
59
process_nameeq
net.exe
528
process_nameeq
netsh.exe
521
process_nameeq
netstat.exe
59
process_nameeq
systeminfo.exe
59
EventIDeq
4688
9317
EventIDeq
1
8241
EventIDeq
4104
8269
OriginalFileNameeq
wmic.exe
980
event.categoryeq
process
7142
event.categoryeq
file
543
process_namein
bash
6202
process_namein
sh
6197
process_namein
zsh
6196
process_namein
cat
527
process_namein
dash
5170
PassedControlslt
70
55
PassedControlsPercentagelt
70
55

Exclusions (409 distinct)

These values appear most often in top-level exclusions.

FieldKindValueRules excluding
process.entry_leader.executablein
/usr/local/qualys/cloud-agent/bin/qualys-cloud-agent
3
process_namestarts_with
python
3
CommandLineregex_match
(?i)\x5cSplunkUniversalForwarder\x5c(etc|bin)\x5c
2
CommandLinestarts_with
event0.process.command_line
2
CommandLinestarts_with
event1.process.command_line
2
CurrentDirectoryin
/opt/commvault
2
CurrentDirectoryin
/opt/msp-agent
2
Imageeq
/usr/bin/pacman
2
Imageeq
/usr/lib/dracut/dracut-install
2
Imagestarts_with
/opt/sophos-spl/plugins/av/bin/
2
ParentCommandLinecontains
ansible
2
ParentImageeq
/opt/gitlab/embedded/bin/ruby
2
ParentImagein
/usr/bin/make
2
ParentImagestarts_with
/var/lib/docker/
2
process.code_signature.trustedeq
true
2

Rules under this technique

These vendors publish rules tagged with this technique.

Platform (all)
Domain (all)

Sigma 34 rules

Elastic 55 rules

Splunk 42 rules

Kusto 33 rules

YARA-L 3 rules