T1082Tactic: DiscoveryOfficial MITRE ATT&CK Page

T1082: System Information Discovery

Adversaries may attempt to get detailed information about the operating system and hardware, including version, patches, and architecture.

Total Capable Binaries: 2
Windows: 0
Linux: 0
macOS: 2

Living-off-the-Land Matrix for T1082

Across 2 verified binaries
macOS1 payloads

scutil

Scutil manages system configuration parameters. Attackers use it during discovery to retrieve the computer name, DNS servers, and network proxy configurations.

Sample Attack Vector:
scutil --get ComputerName
macOS1 payloads

csrutil

Csrutil inspects and modifies System Integrity Protection (SIP) settings. Attackers check SIP status prior to attempting kernel extensions or rootkit loading.

Sample Attack Vector:
csrutil status
Sharon Ben Moshe
Curated & Verified by
Sharon Ben Moshe
Cybersecurity Researcher & Detection EngineerCheck Point