1200KM / detection
T1082 System Information Discovery — Detection Rules
Detection workspace for T1082 System Information Discovery: 31 Sigma sources, 0 Atlas concepts and 0 anomaly models. No live detection validation.
Source-backed rule directory
- Bitbucket User Details Export Attempt Detected · test · medium · {"product":"bitbucket","service":"audit","definition":"Requirements: \"Advance\" log level is required to receive these audit events."}
- Bitbucket User Permissions Export Attempt · test · medium · {"product":"bitbucket","service":"audit","definition":"Requirements: \"Advance\" log level is required to receive these audit events."}
- System Information Discovery - Auditd · test · low · {"product":"linux","service":"auditd"}
- System and Hardware Information Discovery · stable · informational · {"product":"linux","service":"auditd"}
- System Info Discovery via Sysinfo Syscall · experimental · low · {"product":"linux","service":"auditd","definition":"Required auditd configuration:\n-a always,exit -F arch=b64 -S sysinfo -k discovery_sysinfo_syscall\n-a always,exit -F arch=b32 -S sysinfo -k discovery_sysinfo_syscall\n"}
- OS Architecture Discovery Via Grep · test · low · {"category":"process_creation","product":"linux"}
- Potential GobRAT File Discovery Via Grep · test · high · {"category":"process_creation","product":"linux"}
- Container Residence Discovery Via Proc Virtual FS · test · low · {"category":"process_creation","product":"linux"}
- Docker Container Discovery Via Dockerenv Listing · test · low · {"category":"process_creation","product":"linux"}
- Potential Container Discovery Via Inodes Listing · test · low · {"category":"process_creation","product":"linux"}
- System Information Discovery · stable · informational · {"product":"linux","category":"process_creation"}
- System Information Discovery Using Ioreg · test · medium · {"product":"macos","category":"process_creation"}
- System Information Discovery Using sw_vers · test · medium · {"product":"macos","category":"process_creation"}
- System Information Discovery Via Sysctl - MacOS · test · medium · {"product":"macos","category":"process_creation"}
- System Information Discovery Using System_Profiler · test · medium · {"product":"macos","category":"process_creation"}
- Cisco Discovery · test · low · {"product":"cisco","service":"aaa"}
- HackTool - WinPwn Execution - ScriptBlock · test · high · {"category":"ps_script","product":"windows","definition":"Requirements: Script Block Logging must be enabled"}
- System Information Discovery via Registry Queries · experimental · low · {"category":"process_creation","product":"windows"}
- Suspicious Kernel Dump Using Dtrace · test · high · {"product":"windows","category":"process_creation"}
- HackTool - PCHunter Execution · test · high · {"category":"process_creation","product":"windows"}
- HackTool - winPEAS Execution · test · high · {"category":"process_creation","product":"windows"}
- HackTool - WinPwn Execution · test · high · {"category":"process_creation","product":"windows"}
- Suspicious Execution of Hostname · test · low · {"category":"process_creation","product":"windows"}
- Network Reconnaissance Activity · test · high · {"category":"process_creation","product":"windows"}
- PUA - System Informer Execution · test · medium · {"category":"process_creation","product":"windows"}
- Suspicious Query of MachineGUID · test · low · {"category":"process_creation","product":"windows"}
- Potential Suspicious Activity Using SeCEdit · test · medium · {"category":"process_creation","product":"windows"}
- Suspicious Execution of Systeminfo · test · low · {"category":"process_creation","product":"windows"}
- Potential Product Class Reconnaissance Via Wmic.EXE · test · medium · {"category":"process_creation","product":"windows"}
- Uncommon System Information Discovery Via Wmic.EXE · test · medium · {"category":"process_creation","product":"windows"}
- System Disk And Volume Reconnaissance Via Wmic.EXE · test · medium · {"category":"process_creation","product":"windows"}
Atlas deterministic concepts
No exact concept selected.
Anomaly models
No exact Atlas model in this snapshot.
ATT&CK analytic guidance
DET0525 System Discovery via Native and Remote Utilities
AN1452 Analytic 1452
Detection of processes executing system environment inspection operations followed by access to OS configuration APIs or registry locations that expose OS version, architecture, patch level, or hardware characteristics. Defenders observe process execution retrieving system configuration metadata immediately after process startup.
AN1453 Analytic 1453
Execution of system enumeration commands such as `uname`, `df`, `uptime`, `hostname`, `lscpu`, and `cat /etc/os-release` through local terminal or scripts.
AN1454 Analytic 1454
Execution of system info utilities like `systemsetup`, `sw_vers`, `uname`, or `sysctl` by terminal or scripted processes.
AN1455 Analytic 1455
Execution of `esxcli system hostname get`, `esxcli system version get`, or `esxcli hardware` commands through SSH or local shell.
AN1456 Analytic 1456
Use of cloud API calls (e.g., AWS EC2 DescribeInstances, Azure VM Inventory) to enumerate system configurations across assets.
AN1457 Analytic 1457
Execution of `show version`, `show hardware`, or `show system` commands through CLI via SSH or console.
Connected ecosystem references
Linked tags
Simulation, tools and telemetry
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
- Ke3chang · G0004
- Turla · G0010
- Darkhotel · G0012
- admin@338 · G0018
- APT3 · G0022
- APT18 · G0026
- Lazarus Group · G0032
- Sandworm Team · G0034
- Stealth Falcon · G0038
- Patchwork · G0040
- FIN7 · G0046
- Gamaredon Group · G0047
- OilRig · G0049
- APT32 · G0050
- Sowbug · G0054
- Magic Hound · G0059
- FIN8 · G0061
- APT37 · G0067
- MuddyWater · G0069
- APT19 · G0073
- Tropic Trooper · G0081
- APT38 · G0082
- Kimsuky · G0094
- APT41 · G0096
- Inception · G0100
- Wizard Spider · G0102
- Rocke · G0106
- Blue Mockingbird · G0108
- Windshift · G0112
- Sidewinder · G0121
- Windigo · G0124
- Higaisa · G0126
- ZIRCONIUM · G0128
- Mustang Panda · G0129
- TeamTNT · G0139
- Aquatic Panda · G0143
- HEXANE · G1001
- SideCopy · G1008
- Moses Staff · G1009
- CURIUM · G1012
- Scattered Spider · G1015
- FIN13 · G1016
- TA2541 · G1018
- Mustard Tempest · G1020
- Malteiro · G1026
- Daggerfly · G1034
- Winter Vivern · G1035
- Moonstone Sleet · G1036
- RedCurl · G1039
- Play · G1040
- BlackByte · G1043
- APT42 · G1044
- Medusa Group · G1051
- Contagious Interview · G1052
- Storm-0501 · G1053
- MirrorFace · G1054
- VOID MANTICORE · G1055
Existing anomaly research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.