TACTIC: DISCOVERY
System Information Discovery (T1082): real cases
MITRE Definition ↗ Adversaries gather details about the operating system and architecture to guide further exploitation.
Key Facts
Technique ID
T1082
Discovery
Mapped Cases
1
Primary sources
Related Laws
0
Criminal statutes
- ATT&CK Technique Identifier: T1082.
- Tactical Phase: Discovery.
- Substantiated in 1 primary court prosecution cases.
- Every associated case includes verbatim evidentiary excerpts from indictments or sworn affidavits.
Verified Evidentiary Case Records
U.S. v. Yaroslav Vasinskyi (Kaseya VSA / REvil Ransomware)
sentenced 2021-08-11
Primary Source Evidence Excerpt: CISA Advisory AA21-189A
"The REvil dropper checked host architecture and operating system language, aborting execution if Russian locale strings were detected."
U.S. District Court for the Northern District of Texas
View full case dossier →