System Information Discovery

An adversary may attempt to get detailed information about the operating system and hardware, including version, patches, hotfixes, service packs, and architecture. Adversaries may use the information from System Information Discovery during automated discovery to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions.

Tools such as Systeminfo can be used to gather detailed system information. A breakdown of system data can also be gathered through the macOS systemsetup command, but it requires administrative privileges.

Infrastructure as a Service (IaaS) cloud providers such as AWS, GCP, and Azure allow access to instance and virtual machine information via APIs. Successful authenticated API calls can return data such as the operating system platform and status of a particular instance or the model view of a virtual machine.[1][2][3]

ID: T1082
Sub-techniques:  No sub-techniques
Tactic: Discovery
Platforms: IaaS, Linux, Windows, macOS
Permissions Required: User
Data Sources: Command: Command Execution, Instance: Instance Metadata, Process: OS API Execution, Process: Process Creation
Contributors: Praetorian
Version: 2.2
Created: 31 May 2017
Last Modified: 08 March 2021

Procedure Examples

ID Name Description
S0065 4H RAT

4H RAT sends an OS version identifier in its beacons.[4]

G0018 admin@338

admin@338 actors used the following commands after exploiting a machine with LOWBALL malware to obtain information about the OS: ver >> %temp%\download systeminfo >> %temp%\download[5]


ADVSTORESHELL can run Systeminfo to gather information about the victim.[6][7]

S0331 Agent Tesla

Agent Tesla can collect the system's computer name and also has the capability to collect information on the processor, memory, OS, and video card from the system.[8][9][10]

S0504 Anchor

Anchor can determine the hostname and linux version on a compromised host.[11]

S0584 AppleJeus

AppleJeus has collected the victim host information after infection.[12]

G0026 APT18

APT18 can collect system information from the victim’s machine.[13]

G0073 APT19

APT19 collected system architecture information. APT19 used an HTTP malware variant and a Port 22 malware variant to gather the hostname and CPU information from the victim’s machine.[14][15]

G0016 APT29

APT29 used fsutil to check available free space before executing actions that might create large files on disk.[16]

G0022 APT3

APT3 has a tool that can obtain information about the local system.[17][18]

G0050 APT32

APT32 has collected the OS version and computer name from victims. One of the group's backdoors can also query the Windows Registry to gather system information, and another macOS backdoor performs a fingerprint of the machine on its first connection to the C&C server. APT32 executed shellcode to identify the name of the infected host.[19][20][21][22]

G0067 APT37

APT37 collects the computer name, the BIOS model, and execution path.[23]

S0456 Aria-body

Aria-body has the ability to identify the hostname, computer name, Windows version, processor speed, machine GUID, and disk information on a compromised host.[24]

S0373 Astaroth

Astaroth collects the machine name and keyboard language from the system. [25][26]

S0438 Attor

Attor monitors the free disk space on the system.[27]

S0473 Avenger

Avenger has the ability to identify the host volume ID and the OS architecture on a compromised host.[28]

S0344 Azorult

Azorult can collect the machine information, system architecture, the OS version, computer name, Windows product name, the number of CPU cores, video card information, and the system language.[29][30]

S0414 BabyShark

BabyShark has executed the ver command.[31]

S0475 BackConfig

BackConfig has the ability to gather the victim's computer name.[32]

S0093 Backdoor.Oldrea

Backdoor.Oldrea collects information about the OS and computer name.[33]


During its initial execution, BACKSPACE extracts operating system information from the infected host.[34]


BADCALL collects the computer name and host name on the compromised system.[35]

S0337 BadPatch

BadPatch collects the OS system, OS version, MAC address, and the computer name from the victim’s machine.[36]

S0239 Bankshot

Bankshot gathers system information, network addresses, disk type, disk free space, and the operation system version.[37][38]

S0534 Bazar

Bazar can fingerprint architecture, computer name, and OS version on the compromised host. Bazar can also check if the Russian language is installed on the infected machine and terminate if it is found.[39][40]


BISCUIT has a command to collect the processor type, operation system, computer name, uptime, and whether the system is a laptop or PC.[41]

S0268 Bisonal

Bisonal has a command to gather system information from the victim’s machine.[42]

S0089 BlackEnergy

BlackEnergy has used Systeminfo to gather the OS version, as well as information on the system configuration, BIOS, the motherboard, and the processor.[43][44]

S0564 BlackMould

BlackMould can enumerate local drives on a compromised host.[45]


BLINDINGCAN has collected from a victim machine the system name, processor information, OS version, and disk information, including type and free space available.[46]

G0108 Blue Mockingbird

Blue Mockingbird has collected hardware details for the victim's system, including CPU and memory information.[47]

S0486 Bonadan

Bonadan has discovered the OS version, CPU model, and RAM size of the system it has been installed on.[48]

S0252 Brave Prince

Brave Prince collects hard drive content and system configuration information.[49]


BUBBLEWRAP collects system information, including the operating system version and hostname.[5]

S0471 build_downer

build_downer has the ability to send system volume information to C2.[28]

S0482 Bundlore

Bundlore will enumerate the macOS version to determine which follow-on behaviors to execute.[50]

S0454 Cadelspy

Cadelspy has the ability to discover information about the compromised host.[51]

S0351 Cannon

Cannon can gather system information from the victim’s machine such as the OS version, machine name, and drive information.[52][53]

S0484 Carberp

Carberp has collected the operating system version from the infected system.[54]

S0348 Cardinal RAT

Cardinal RAT can collect the hostname, Microsoft Windows version, and processor architecture from a victim machine.[55]


CARROTBAT has the ability to determine the operating system of the compromised host and whether Windows is being run with x86 or x64 architecture.[56][57]

S0572 Caterpillar WebShell

Caterpillar WebShell has a module to gather information from the compromrised asset, including the computer version, computer name, IIS version, and more.[58]

S0144 ChChes

ChChes collects the victim hostname, window resolution, and Microsoft Windows version.[59][60]

G0114 Chimera

Chimera has used fsutil, fsinfo drives systeminfo, and vssadmin list shadows for sytesm information including shadow volumes and drive information.[61]

S0106 cmd

cmd can be used to find information about the operating system.[62]

S0244 Comnie

Comnie collects the hostname of the victim machine.[63]


CORESHELL collects hostname, volume serial number and OS version data from the victim and sends the information to its C2 server.[64]

S0046 CozyCar

A system info module in CozyCar gathers information on the victim host’s configuration.[65]

S0488 CrackMapExec

CrackMapExec can enumerate the system drives and associated system name.[66]

S0115 Crimson

Crimson contains a command to collect the victim PC name and operating system.[67]

S0334 DarkComet

DarkComet can collect the computer name, RAM used, and operating system version from the victim’s machine.[68][69]

G0012 Darkhotel

Darkhotel has collected the hostname, OS version, service pack version, and the processor architecture from the victim’s machine.[70][71]

S0354 Denis

Denis collects OS information and the computer name from the victim’s machine.[72][73]

S0021 Derusbi

Derusbi gathers the name of the local host, version of GNU Compiler Collection (GCC), and the system information about the CPU, machine, and operating system.[74]

S0472 down_new

down_new has the ability to identify the system volume information of a compromised host.[28]

S0186 DownPaper

DownPaper collects the victim host name and serial number, and then sends the information to the C2 server.[75]

S0547 DropBook

DropBook has checked for the presence of Arabic language in the infected machine's settings.[76]

S0567 Dtrack

Dtrack can collect the victim's computer name, hostname and adapter information to create a unique identifier.[77][78]

S0062 DustySky

DustySky extracts basic information about the operating system.[79]

S0024 Dyre

Dyre has the ability to identify the computer name, OS version, and hardware configuration on a compromised host.[80]

S0554 Egregor

Egregor can perform a language check of the infected system and can query the CPU information (cupid).[81][82]

S0081 Elise

Elise executes systeminfo after initial communication is made to the remote server.[83]

S0082 Emissary

Emissary has the capability to execute ver, systeminfo, and gpresult commands.[84]

S0363 Empire

Empire can enumerate host system information like OS, architecture, applied patches, and more.[85]

S0091 Epic

Epic collects the OS version, hardware information, computer name, available system memory status, disk space information, and system and user language settings.[86]


EVILNUM can obtain the computer name from the victim's system.[87]

S0569 Explosive

Explosive has collected the computer name from the infected host.[88]


FALLCHILL can collect operating system (OS) version information, processor information, system name, and information about installed disks from the victim.[89]

S0512 FatDuke

FatDuke can collect the user name, Windows version, computer name, and available space on discs from a compromised host.[90]

S0171 Felismus

Felismus collects the system information, including hostname and OS version, and sends it to the C2 server.[91]


FELIXROOT collects the victim’s computer name, processor architecture, OS version, volume serial number, and system type.[92][93]

S0355 Final1stspy

Final1stspy obtains victim Microsoft Windows version information and CPU architecture.[94]

S0182 FinFisher

FinFisher checks if the victim OS is 32 or 64-bit.[95][96]

S0381 FlawedAmmyy

FlawedAmmyy beacons out the victim operating system and computer name during the initial infection.[97]

G0101 Frankenstein

Frankenstein has enumerated hosts, looking for the system's machine name.[98]

S0410 Fysbis

Fysbis has used the command ls /etc | egrep -e"fedora*|debian*|gentoo*|mandriva*|mandrake*|meego*|redhat*|lsb-*|sun-*|SUSE*|release" to determine which Linux OS version is running.[99]

G0047 Gamaredon Group

A Gamaredon Group file stealer can gather the victim's computer name and drive serial numbers to send to a C2 server.[100][101]

S0460 Get2

Get2 has the ability to identify the computer name and Windows version of an infected host.[102]

S0032 gh0st RAT

gh0st RAT has gathered system architecture, processor, OS configuration, and installed hardware information.[103]

S0249 Gold Dragon

Gold Dragon collects endpoint information using the systeminfo command.[49]

S0493 GoldenSpy

GoldenSpy has gathered operating system information.[104]

S0531 Grandoreiro

Grandoreiro can collect the computer name and OS version from a compromised host.[105]

S0237 GravityRAT

GravityRAT collects the MAC address, computer name, and CPU information.[106]


GRIFFON has used a reconnaissance module that can be used to retrieve information about a victim's computer, including the resolution of the workstation .[107]


HALFBAKED can obtain information about the OS, processor, and BIOS.[108]


can collect system information, including computer name, system manufacturer, IsDebuggerPresent state, and execution path.[109]


HAWKBALL can collect the OS version, architecture information, and computer name.[110]

G0126 Higaisa

Higaisa collected the system volume serial number, GUID, and computer name.[111][112]

S0601 Hildegard

Hildegard has collected the host's OS, CPU, and memory information.[113]

G0072 Honeybee

Honeybee gathers computer name and information using the systeminfo command.[114]


HOPLIGHT has been observed collecting victim machine information like OS version, drivers, volume information and more.[115]

S0431 HotCroissant

HotCroissant has the ability to determine if the current user is an administrator, Windows product name, processor name, screen resolution, and physical RAM of the infected host.[116]

S0203 Hydraq

Hydraq creates a backdoor through which remote attackers can retrieve information such as computer name, OS version, processor speed, memory size, and CPU speed.[117]

S0483 IcedID

IcedID has the ability to identify the computer name and OS version on a compromised host.[118]

G0100 Inception

Inception has used a reconnaissance module to gather information about the operating system and hardware on the infected host.[119]

S0259 InnaputRAT

InnaputRAT gathers volume drive information and system information.[120]

S0260 InvisiMole

InvisiMole can gather information on the mapped drives, OS version, computer name, DEP policy, memory size, and system volume serial number.[121][122]

S0015 Ixeshe

Ixeshe collects the computer name of the victim's system during the initial infection.[123]


JHUHUGIT obtains a build identifier as well as victim hard drive information from Windows registry key HKLM\SYSTEM\CurrentControlSet\Services\Disk\Enum. Another JHUHUGIT variant gathers the victim storage volume serial number and the storage device name.[124][125]

S0201 JPIN

JPIN can obtain system information such as OS version and disk space.[126]

S0283 jRAT

jRAT collects information about the OS (version, build type, install date) as well as system up-time upon receiving a connection from a backdoor.[127]


KARAE can collect system information.[109]

S0088 Kasidet

Kasidet has the ability to obtain a victim's system name and operating system version.[128]

S0265 Kazuar

Kazuar gathers information on the system and local drives.[129]

G0004 Ke3chang

Ke3chang performs operating system information discovery using systeminfo.[130][131]

S0487 Kessel

Kessel has collected the system architecture, OS version, and MAC address information.[48]

S0387 KeyBoy

KeyBoy can gather extended system information, such as information about the operating system, disks, and memory.[132][133]


KEYMARBLE has the capability to collect the computer name, language settings, the OS version, CPU information, disk devices, and time elapsed since system start.[134]


KGH_SPY can collect drive information from a compromised host.[135]

G0094 Kimsuky

Kimsuky has gathered information about the infected computer.[136]


KOMPROGO is capable of retrieving information about the infected system.[137]


KONNI can gather the OS version, architecture information, connected drives, hostname, and computer name from the victim’s machine and has used systeminfo.exe to get a snapshot of the current system state of the target machine.[138][139]

S0236 Kwampirs

Kwampirs collects OS version information such as registered owner details, manufacturer details, processor type, available storage, installed patches, hostname, version info, system date, and other system information by using the commands systeminfo, net config workstation, hostname, ver, set, and date /t.[140]

G0032 Lazarus Group

Several Lazarus Group malware families collect information on the type and version of the victim OS, as well as the victim computer name and CPU information. A Destover-like variant used by Lazarus Group also collects disk space information and sends it to its C2 server.[141][142][143][144][145].

S0395 LightNeuron

LightNeuron gathers the victim computer name using the Win32 API call GetComputerName.[146]

S0211 Linfo

Linfo creates a backdoor through which remote attackers can retrieve system information.[147]

S0447 Lokibot

Lokibot has the ability to discover the computer name and Windows product name/version.[148]

S0451 LoudMiner

LoudMiner has monitored CPU usage.[149]

S0532 Lucifer

Lucifer can collect the computer name, system architecture, default language, and processor frequency of a compromised host.[150]

S0409 Machete

Machete collects the hostname of the target computer.[151]

G0059 Magic Hound

Magic Hound malware has used a PowerShell command to check the victim system architecture to determine if it is an x64 machine. Other malware has obtained the OS version, UUID, and computer/host name to send to the C2 server.[152]

S0449 Maze

Maze has checked the language of the infected system using the "GetUSerDefaultUILanguage" function.[153]

S0455 Metamorfo

Metamorfo has collected the hostname and Operating System version from the system.[154][155]

S0339 Micropsia

Micropsia gathers the hostname and OS version from the victim’s machine.[156][157]

S0051 MiniDuke

MiniDuke can gather the hostname on a compromised machine.[90]

S0280 MirageFox

MirageFox can collect CPU and architecture information from the victim’s machine.[158]

S0084 Mis-Type

The initial beacon packet for Mis-Type contains the operating system version and file system of the victim.[159]

S0083 Misdat

The initial beacon packet for Misdat contains the operating system version of the victim.[159]

S0079 MobileOrder

MobileOrder has a command to upload to its C2 server victim mobile device information, including IMEI, IMSI, SIM card serial number, phone number, Android version, and other information.[160]

S0553 MoleNet

MoleNet can collect information about the about the system.[76]

S0149 MoonWind

MoonWind can obtain the victim hostname, Windows version, RAM amount, number of drives, and screen resolution.[161]

S0284 More_eggs

More_eggs has the capability to gather the OS version and computer name.[162][163]

G0069 MuddyWater

MuddyWater has used malware that can collect the victim’s OS version and machine name.[164][165][166][167]


MURKYTOP has the capability to retrieve information about the OS.[168]

G0129 Mustang Panda

Mustang Panda has gathered system information using systeminfo.[169]

S0205 Naid

Naid collects a unique identifier (UID) from a compromised host.[170]

S0228 NanHaiShu

NanHaiShu can gather the victim computer name and serial number.[171]

S0247 NavRAT

NavRAT uses systeminfo on a victim’s machine.[172]

S0272 NDiskMonitor

NDiskMonitor obtains the victim computer name and encrypts the information to send over its C2 channel.[173]

S0457 Netwalker

Netwalker can determine the system architecture it is running on to choose which version of the DLL to use.[174]


NETWIRE can discover and collect victim system information.[175]

S0385 njRAT

njRAT enumerates the victim operating system and computer name during the initial infection.[176]


NOKKI can gather information on drives and the operating system on the victim’s machine.[177]

S0346 OceanSalt

OceanSalt can collect the computer name from the system.[178]

S0340 Octopus

Octopus collects system drive information, the computer name, and the size of the disk.[179]

G0049 OilRig

OilRig has run hostname and systeminfo on a victim.[180][181][182]

S0439 Okrum

Okrum can collect computer name, locale information, and information about the OS and architecture.[183]

S0264 OopsIE

OopsIE checks for information on the CPU fan, temperature, mouse, hard disk, and motherboard as part of its anti-VM checks.[184]

G0116 Operation Wocao

Operation Wocao has discovered the local disks attached to the system and their hardware information including manufacturer and model, as well as the OS versions of systems connected to a targeted network.[185]

S0229 Orz

Orz can gather the victim OS version and whether it is 64 or 32 bit.[171]

S0165 OSInfo

OSInfo discovers information about the infected machine.[17]

S0402 OSX/Shlayer

OSX/Shlayer can collect the macOS version and IOPlatformUUID.[186]


OSX_OCEANLOTUS.D collects processor information, memory information, computer name, hardware UUID, serial number, and operating system version.[187][188]

S0208 Pasam

Pasam creates a backdoor through which remote attackers can retrieve information such as hostname and free disk space.[189]

G0040 Patchwork

Patchwork collected the victim computer name, OS version, and architecture type and sent the information to its C2 server. Patchwork also enumerated all available drives on the victim's machine.[190][173]

S0556 Pay2Key

Pay2Key has the ability to gather the hostname of the victim machine.[191]

S0587 Penquin

Penquin can report the file system type and disk space of a compromised host to C2.[192]

S0048 PinchDuke

PinchDuke gathers system configuration information.[193]

S0501 PipeMon

PipeMon can collect and send OS version and computer name as a part of its C2 beacon.[194]

S0124 Pisloader

Pisloader has a command to collect victim system information, including the system name and OS version.[195]


PLAINTEE collects general system enumeration data about the infected machine and checks the OS version.[196]

S0428 PoetRAT

PoetRAT has the ability to gather information about the compromised host.[197]

S0453 Pony

Pony has collected the Service Pack, language, and region information to send to the C2.[198]


POORAIM can identify system information, including battery status.[109]

S0378 PoshC2

PoshC2 contains modules, such as Get-ComputerInfo, for enumerating common system information.[199]

S0139 PowerDuke

PowerDuke has commands to get information about the victim's name, build, version, serial number, and memory usage.[200]

S0441 PowerShower

PowerShower has collected system information on the infected host.[201]


POWERSTATS can retrieve OS name/architecture and computer/domain name information from compromised hosts.[202][203]


POWRUNER may collect information about the system by running hostname and systeminfo on a victim.[204]

S0113 Prikormka

A module in Prikormka collects information from the victim about Windows OS version, computer name, battery info, and physical memory.[205]

S0238 Proxysvc

Proxysvc collects the OS version, country name, MAC address, computer name, physical memory statistics, and volume information for all drives on the system.[145]


PUNCHBUGGY can gather system information such as computer names.[206]

S0192 Pupy

Pupy can grab a system’s information including the OS version, architecture, etc.[207]

S0262 QuasarRAT

QuasarRAT has a command to gather system information from the victim’s machine.[208]

S0458 Ramsay

Ramsay can detect system information--including disk names, total space, and remaining space--to create a hardware profile GUID which acts as a system identifier for operators.[209][210]


RATANKBA gathers information about the OS architecture, OS name, and OS version/Service pack.[211][212]

S0172 Reaver

Reaver collects system information from the victim, including CPU speed, computer name, volume serial number, ANSI code page, OEM code page identifier for the OS, Microsoft Windows version, and memory information.[213]

S0153 RedLeaves

RedLeaves can gather extended system information including the hostname, OS version number, platform, memory information, time elapsed since system startup, and CPU information.[60][214]

S0125 Remsec

Remsec can obtain the OS version information, computer name, processor architecture, machine role, and OS edition.[215]

S0379 Revenge RAT

Revenge RAT collects the CPU information, OS information, and system language.[216]

S0496 REvil

REvil can identify the username, machine name, system language, keyboard layout, OS version, and system drive information on a compromised host.[217][218][219][220][220][221][222][223]

S0433 Rifdoor

Rifdoor has the ability to identify the Windows version on the compromised host.[224]

S0448 Rising Sun

Rising Sun can detect the computer name, operating system, and other native system information.[225]

G0106 Rocke

Rocke has used uname -m to collect the name and information about the infected system's kernel.[226]

S0270 RogueRobin

RogueRobin gathers BIOS versions and manufacturers, the number of CPU cores, the total physical memory, and the computer name.[227]


ROKRAT gathers the computer name and checks the OS version to ensure it doesn’t run on a Windows XP or Windows Server 2003 systems.[228][229][230][231]

S0148 RTM

RTM can obtain the computer name, OS version, and default language identifier.[232]

S0253 RunningRAT

RunningRAT gathers the OS version, logical drives information, processor information, and volume information.[49]

S0085 S-Type

The initial beacon packet for S-Type contains the operating system version and file system of the victim.[159]

G0034 Sandworm Team

Sandworm Team used a backdoor to enumerate information about the infected system's operating system.[233][234]

S0461 SDBbot

SDBbot has the ability to identify the OS version, country code, and computer name.[102]

S0382 ServHelper

ServHelper will attempt to enumerate Windows version and system architecture.[235]

S0596 ShadowPad

ShadowPad has discovered system information including memory status, CPU frequency, OS versions, and volume serial numbers.[236]

S0140 Shamoon

Shamoon obtains the victim's operating system version and keyboard layout and sends the information to the C2 server.[237][238]

S0546 SharpStage

SharpStage has checked the system settings to see if Arabic is the configured language.[239]


SHARPSTATS has the ability to identify the IP address, machine name, and OS of the compromised host.[203]

S0445 ShimRatReporter

ShimRatReporter gathered the operating system name and specific Windows version of an infected machine.[240]


SHUTTERSPEED can collect system information.[109]

G0121 Sidewinder

Sidewinder has used tools to collect the computer name, OS version, installed hotfixes, as well as information regarding the memory and processor on a compromised host.[241][242]

S0468 Skidmap

Skidmap has the ability to check whether the infected system’s OS is Debian or RHEL/CentOS to determine which cryptocurrency miner it should use.[243]


SLOTHFULMEDIA has collected system name, OS version, adapter information, memory usage, and disk information from a victim machine.[244]


SLOWDRIFT collects and sends system information to its C2.[109]

S0516 SoreFang

SoreFang can collect the hostname, operating system configuration, product ID, and disk space on victim machines by executing Systeminfo.[245]


SOUNDBITE is capable of gathering system information.[137]

G0054 Sowbug

Sowbug obtained OS version and hardware configuration from a victim.[246]

S0543 Spark

Spark can collect the hostname, keyboard layout, and language from the system.[247]

S0374 SpeakUp

SpeakUp uses the cat /proc/cpuinfo | grep -c "cpu family" 2>&1 command to gather system information. [248]

S0058 SslMM

SslMM sends information to its hard-coded C2, including OS version, service pack information, processor speed, system name, and OS install date.[249]

G0038 Stealth Falcon

Stealth Falcon malware gathers system information via WMI, including the system directory, build number, serial number, version, manufacturer, model, and total physical memory.[250]

S0380 StoneDrill

StoneDrill has the capability to discover the system OS, Windows version, architecture and environment.[251]

S0142 StreamEx

StreamEx has the ability to enumerate system information.[252]

S0491 StrongPity

StrongPity can identify the hard disk volume serial number on a compromised host.[253]


SUNBURST collected hostname, OS version, and device uptime.[254][255]

S0242 SynAck

SynAck gathers computer names, OS version info, and also checks installed keyboard layouts to estimate if it has been launched from a certain list of countries.[256]

S0060 Sys10

Sys10 collects the computer name, OS versioning information, and OS install date and sends the information to the C2.[249]


SYSCON has the ability to use Systeminfo to identify system information.[57]

S0096 Systeminfo

Systeminfo can be used to gather information about the operating system.[257]

S0098 T9000

T9000 gathers and beacons the operating system build number and CPU Architecture (32-bit/64-bit) during installation.[258]


TAINTEDSCRIBE can use DriveList to retrieve drive information.[259]

S0467 TajMahal

TajMahal has the ability to identify hardware information, the computer name, and OS information on an infected host.[260]

S0266 TrickBot

TrickBot gathers the OS version, machine name, CPU type, amount of RAM available, and UEFI/BIOS firmware information from the victim’s machine.[261][262][263][264]

S0094 Trojan.Karagany

Trojan.Karagany can capture information regarding the victim's OS, security, and hardware configuration.[265]

G0081 Tropic Trooper

Tropic Trooper has detected a target system’s OS version and system volume information.[266][267]

G0010 Turla

Turla surveys a system upon check-in to discover operating system configuration details using the systeminfo, gpresult, and set commands.[268][269]


TURNEDUP is capable of gathering system information.[270]


TYPEFRAME can gather the disk volume information.[271]

S0130 Unknown Logger

Unknown Logger can obtain information about the victim computer name, physical memory, country, and date.[272]


UPPERCUT has the capability to gather the system’s hostname and OS version.[273]

S0386 Ursnif

Ursnif has used Systeminfo to gather system information.[274]

S0476 Valak

Valak can determine the Windows version and computer name on a compromised host.[275][276]


VERMIN collects the OS name, machine name, and architecture information.[277]

S0180 Volgmer

Volgmer can gather system information, the computer name, OS version, drive and serial information from the victim's machine.[278][279][280]

S0514 WellMess

WellMess can identify the computer name of a compromised host.[281][282]

G0124 Windigo

Windigo has used a script to detect which Linux distribution and version is currently installed on the system.[48]


WINDSHIELD can gather the victim computer name.[137]

G0112 Windshift

Windshift has used malware to identify the computer name of a compromised host.[283]


WINERACK can gather information about the host.[109]

S0176 Wingbird

Wingbird checks the victim OS version after executing to determine where to drop files based on whether the victim is 32-bit or 64-bit.[284]

S0059 WinMM

WinMM collects the system name, OS version including service pack, and system install date and sends the information to the C2 server.[249]

G0102 Wizard Spider

Wizard Spider has used "systeminfo" and similar commands to acquire detailed configuration information of a victim machine.[285]

S0161 XAgentOSX

XAgentOSX contains the getInstalledAPP function to run ls -la /Applications to gather what applications are installed.[286]


YAHOYAH checks for the system’s Windows OS version and hostname.[266]

S0248 yty

yty gathers the computer name, the serial number of the main disk volume, CPU information, Microsoft Windows version, and runs the command systeminfo.[287]

S0251 Zebrocy

Zebrocy collects the OS version, computer name and serial number for the storage volume C:. Zebrocy also runs the systeminfo command to gather system information. [288][52][289][53][290][291][292]

S0230 ZeroT

ZeroT gathers the victim's computer name, Windows version, and system language, and then sends it to its C2 server.[293]

S0330 Zeus Panda

Zeus Panda collects the OS version, system architecture, computer name, product ID, install date, and information on the keyboard mapping to determine the language used on the system.[294][295]


ZIRCONIUM has used a tool to capture the processor architecture of a compromised host in order to register it with C2.[296]

S0086 ZLib

ZLib has the ability to enumerate system information.[159]

S0350 zwShell

zwShell can obtain the victim PC name and OS version.[297]

S0412 ZxShell

ZxShell can collect the local hostname, operating system details, CPU speed, and total physical memory.[298]


This type of attack technique cannot be easily mitigated with preventive controls since it is based on the abuse of system features.


System and network discovery techniques normally occur throughout an operation as an adversary learns the environment. Data and events should not be viewed in isolation, but as part of a chain of behavior that could lead to other activities based on the information obtained.

Monitor processes and command-line arguments for actions that could be taken to gather system and network information. Remote access tools with built-in features may interact directly with the Windows API to gather information. Information may also be acquired through Windows system management tools such as Windows Management Instrumentation and PowerShell.

In cloud-based systems, native logging can be used to identify access to certain APIs and dashboards that may contain system information. Depending on how the environment is used, that data alone may not be useful due to benign use during normal operations.


