1200KM / simulation
T1614.001 System Language Discovery — Attack Simulation
Adversaries may attempt to gather information about the system language of a victim in order to infer the geographical location of that host. This information may be used to shape follow-on behaviors, including whether the adversary infects the target and/or attempts specific actions. This decision may be employed by malware developers and operators to reduce their risk of attracting the attention of specific law enforcement agencies or…
Technique description
Adversaries may attempt to gather information about the system language of a victim in order to infer the geographical location of that host. This information may be used to shape follow-on behaviors, including whether the adversary infects the target and/or attempts specific actions. This decision may be employed by malware developers and operators to reduce their risk of attracting the attention of specific law enforcement agencies or…
At least one platform-compatible Atomic procedure is documented. Individual review, lab prerequisites, and validation remain required.
Official ATT&CK definition · Detection rules and anomaly models
Documented simulation candidates
- Discover System Language with localectl
Procedure 07ce871a-b3c3-44a3-97fa-a20118fdc7c9; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Discover System Language with Powershell
Procedure 1f23bfe8-36d4-49ce-903a-19a1e8c6631b; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Discover System Language with WMIC
Procedure 4758003d-db14-4959-9c0f-9e87558ac69e; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Discover System Language by locale file
Procedure 5d7057c9-2c8a-4026-91dd-13b5584daa69; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Discover System Language by Registry Query
Procedure 631d4cf1-42c9-4209-8fe9-6bd4de9421be; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Discover System Language with dism.exe
Procedure 69f625ba-938f-4900-bdff-82ada3df5d9c; elevation required; cleanup not declared. Not executed or individually validated.
- Discover System Language with locale
Procedure 837d609b-845e-4519-90ce-edc3b4b0e138; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Discover System Language by Environment Variable Query
Procedure cb8f7cdc-36c4-4ed0-befc-7ad7d24dfd7a; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Discover System Language with chcp
Procedure d91473ca-944e-477a-b484-0e80217cd789; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Discover System Language by Windows API Query
Procedure e39b99e9-ce7f-4b24-9c88-0fbad069e6c6; elevation not declared required; cleanup not declared. Not executed or individually validated.
Connected ecosystem references
Linked tags
Detection and collection
Attack tools
No reviewed association in this snapshot.
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
Existing research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.