Remote System Information Discovery

An adversary may attempt to get detailed information about remote systems and their peripherals, such as make/model, role, and configuration. Adversaries may use information from Remote System Information Discovery to aid in targeting and shaping follow-on behaviors. For example, the systems operational role and model information can dictate whether it is a relevant target for the adversarys operational objectives. In addition, the systems configuration may be used to scope subsequent technique usage. Requests for system information are typically implemented using automation and management protocols and are often automatically requested by vendor software during normal operation. This information may be used to tailor management actions, such as program download and system or module firmware. An adversary may leverage this same information by issuing calls directly to the systems API.

ID: T0888
Sub-techniques:  No sub-techniques
Tactic: Discovery
Platforms: Field Controller/RTU/PLC/IED, Safety Instrumented System/Protection Relay
Version: 1.0
Created: 13 April 2021
Last Modified: 06 May 2022

Procedure Examples

ID Name Description
S0093 Backdoor.Oldrea

The Backdoor.Oldrea payload gathers server information that includes CLSID, server name, Program ID, OPC version, vendor information, running state, group count, and server bandwidth. This information helps indicate the role the server has in the control process. [1] [2]

S0604 Industroyer

Industroyer IEC 60870-5-104 module includes a range mode to discover Information Object Addresses (IOAs) by enumerating through each. [3]

S0604 Industroyer

Industroyer's OPC DA module also uses IOPCBrowseServerAddressSpace to look for items with the following strings: \ctlSelOn\, \ctlOperOn\, \ctlSelOff\, \ctlOperOff\, \\Pos and stVal. [3]

S0604 Industroyer

The IndustroyerIEC 61850 componentsends the domain-specific MMSgetNameListrequest to determine what logical nodes the device supports. It then searches the logical nodes for the CSW value, which indicates the device performs a circuit breaker or switch control function. [3]

S0603 Stuxnet

Stuxnet enumerates and parses the System Data Blocks (SDB) using the s7blk_findfirst and s7blk_findnext API calls in s7otbxdx.dll. Stuxnet must find an SDB with the DWORD at offset 50h equal to 0100CB2Ch. This specifies that the system uses the Profibus communications processor module CP 342-5. In addition, specific values are searched for and counted: 7050h and 9500h. 7050h is assigned to part number KFC750V3 which appears to be a frequency converter drive (also known as variable frequency drive) manufactured by Fararo Paya in Teheran, Iran. 9500h is assigned to Vacon NX frequency converter drives manufactured by Vacon based in Finland. [4]


ID Mitigation Description
M0814 Static Network Configuration

ICS environments typically have more statically defined devices, therefore minimize the use of both IT discovery protocols (e.g., DHCP, LLDP) and discovery functions in automation protocols. [5] [6] Examples of automation protocols with discovery capabilities include OPC UA Device Discovery [7], BACnet [8], and Ethernet/IP. [9]


ID Data Source Data Component
DS0015 Application Log Application Log Content
DS0029 Network Traffic Network Traffic Content