System Location Discovery T1614

Tactic: Discovery

Adversaries may gather information in an attempt to calculate the geographical location of a victim host. Adversaries may use the information from System Location Discovery during automated discovery to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions.

Events covered

3 catalog events are tagged with this technique by at least one rule.

Authoring guide

These 6 rules share fields, values, and exclusions.

Fields filtered most (15 distinct)

These fields appear most often in rule filters.

FieldRulesHowSample values
CommandLine4regex_match 2, contains 1, ends_with 1(?i)chcp\s+?$, chcp, chcp , chcp , control\nls\language
process_name4regex_match 2, eq 1, is_not_null 1(?i)chcp\.com, net.exe, net1.exe, tzutil.exe
EventID2eq 21, 4688
Image2ends_with 2\chcp.com, \reg.exe
host.os.type2eq 2
parent_process_name2regex_match 2(?i)(powershell|pwsh|cmd)\.exe
DestinationPortName1eq 1dns
EventType1eq 1lookup_requested
OriginalFileName1eq 1reg.exe
ParentCommandLine1contains 1 -c , -k , -r
ParentImage1ends_with 1\cmd.exe
QueryName1wildcard 1*api.ipify.org, *checkip.amazonaws.com, *checkip.dyndns.org
Type1eq 1
event.type1eq 1start
process.args1eq 1/g, /tz, time

Top indicator values (45 distinct)

These values appear most often in rule predicates.

FieldKindValueRules (here)Corpus reach
CommandLineregex_match
(?i)chcp\s+?$
22
parent_process_nameregex_match
(?i)(powershell|pwsh|cmd)\.exe
22
process_nameregex_match
(?i)chcp\.com
22
CommandLinecontains
control\nls\language
1
CommandLinecontains
query
18
CommandLineends_with
chcp
1
CommandLineends_with
chcp
1
CommandLineends_with
chcp
1
DestinationPortNameeq
dns
15
EventIDeq
1
1241
EventIDeq
4688
1317
EventTypeeq
lookup_requested
18
Imageends_with
\chcp.com
12
Imageends_with
\reg.exe
158
OriginalFileNameeq
reg.exe
143
ParentCommandLinecontains
-c
1
ParentCommandLinecontains
-k
1
ParentCommandLinecontains
-r
1
ParentImageends_with
\cmd.exe
120
QueryNamewildcard
*api.ipify.org
13
QueryNamewildcard
*checkip.amazonaws.com
13
QueryNamewildcard
*checkip.dyndns.org
13
QueryNamewildcard
*freegeoip.app
13
QueryNamewildcard
*icanhazip.com
13
QueryNamewildcard
*ifconfig.*
1
QueryNamewildcard
*ip-lookup.net
1
QueryNamewildcard
*ip.anysrc.net
1
QueryNamewildcard
*ipapi.co
1
QueryNamewildcard
*ipecho.net
13
QueryNamewildcard
*ipgeoapi.com
1

Exclusions (30 distinct)

These values appear most often in top-level exclusions.

FieldKindValueRules excluding
userregex_match
\$$
2
Imagewildcard
?:\program files (x86)\*.exe
1
Imagewildcard
?:\program files\*.exe
1
Imagewildcard
?:\programdata\microsoft\windows defender\platform\*\msmpeng.exe
1
Imagewildcard
?:\users\*\appdata\local\google\chrome\application\chrome.exe
1
Imagewildcard
?:\users\*\appdata\local\microsoft\onedrive\onedrive.exe
1
Imagewildcard
?:\users\*\appdata\local\programs\fiddler\fiddler.exe
1
Imagewildcard
?:\users\*\appdata\local\programs\microsoft vs code\code.exe
1
Imagewildcard
?:\windows\prey\versions\*\bin\node.exe
1
Imagewildcard
?:\windows\system32\microsoftedgecp.exe
1
Imagewildcard
?:\windows\system32\smartscreen.exe
1
Imagewildcard
?:\windows\system32\wwahost.exe
1
Signatureeq
brave software, inc.
1
Signatureeq
evernote corporation
1
Signatureeq
loom, inc.
1

Rules under this technique

These vendors publish rules tagged with this technique.

Platform: Windows

Domain: Endpoint

Sigma 2 rules

Elastic 2 rules

Splunk 2 rules