TACTIC: DISCOVERY

System Information Discovery (T1082): real cases

MITRE Definition ↗
Adversaries gather details about the operating system and architecture to guide further exploitation.

Key Facts

Technique ID
T1082
Discovery
Mapped Cases
1
Primary sources
Related Laws
0
Criminal statutes
  • ATT&CK Technique Identifier: T1082.
  • Tactical Phase: Discovery.
  • Substantiated in 1 primary court prosecution cases.
  • Every associated case includes verbatim evidentiary excerpts from indictments or sworn affidavits.

Verified Evidentiary Case Records

Primary Source Evidence Excerpt: CISA Advisory AA21-189A
"The REvil dropper checked host architecture and operating system language, aborting execution if Russian locale strings were detected."
U.S. District Court for the Northern District of Texas View full case dossier →