One real attacker move, a safe way to run it on a machine you own, and the detection that closes the gap — in that order, so you leave with better coverage than you arrived with.
technique T1082 · System Information Discoveryseen in Black Bastawhere any Windows box
What this is about
Can your SOC see an attacker taking inventory?
Before an intruder decides what to do with a machine, they ask it what it is. systeminfo answers in one screen: the Windows build, the domain, the patch level, the memory, the boot time. It is the same command a help-desk engineer runs, and it is the first thing a hands-on attacker runs after landing.
The detection does not try to ban the tool — plenty of legitimate work needs it. It watches for the execution, so that when a box is inventoried by something that has no reason to inventory it, a human gets to look at the timing and the parent process.
The detection watches one thing: the built-in systeminfo tool being run to read the machine's full specification.
This is not hypothetical
The Black Basta ransomware operation is documented performing system information discovery on machines it reaches. Knowing the build and the patch level tells the operator which privilege-escalation path is likely to work; knowing the memory and the role tells them whether this box is worth encrypting or worth keeping quiet.
There is no malware in this step and nothing to quarantine. It is one built-in command, run by an ordinary account — the same line you are about to run yourself.
The actor above is named in MITRE ATT&CK’s own Procedure Examples for this technique; the link is where you can read it. Nothing on this page discloses a move an attacker does not already have — it just makes sure the defender has it too.
Build, domain, hotfixes, memory, uptime. An attacker learns in a second what would take them an hour of poking around.
Nothing to block
systeminfo ships with Windows and your own staff use it. The signal is who ran it, from what, and when — never the file itself.
It comes before the decision
The inventory is how an intruder picks the escalation path and the target. Catching it buys you the time before they act.
The test
Run the real thing. Safely. On a box you own.
Run the same inventory an intruder runs, then open your own alerts.
01
Take the inventory
Run systeminfo — the built-in that prints the machine's full specification in one go. This is the moment your SOC should notice.
02
Read what it told you
Look at the output the way an attacker would: build number, domain membership, installed hotfixes. That is the map they just got for free.
03
Check your alerts
Open your SOC or EDR. Did system information discovery fire — or was the machine sized up in silence?
test-your-soc-system-info.ps1 · PowerShell · a machine you own
# test-your-soc-system-info.ps1 — run on a machine you own.
# Safe: one read-only lookup. Nothing is created, changed or deleted.
# STEP 1 - the inventory an intruder takes the minute they land.
systeminfo
# STEP 2 - open your SOC / EDR. Did system information discovery alert?
One read-only command that prints the machine's own specification. Nothing is created, changed or deleted, so there is nothing to undo and no admin rights are needed.
Reading the result — honestly
Something fired
Your tooling watches for machines being inventoried
Good — an intruder sizing up a box would surface the same way. On to the next one.
Silence
The inventory passed unseen — now you know
Not a verdict on your team; a specific, fixable gap you just found in a minute. The detection below is exactly what to hand them to close it.
Straight with you: we never see your alerts — you’re the judge, which is also why we never touch your data. And a lab isn’t production; a test box often logs differently than the real fleet. "It fired" means your EDR flagged systeminfo running — note that a lone run is often legitimate, so the valuable catch is systeminfo launched by an unexpected parent, or alongside other discovery commands in the same minute. Treat a pass as a reason to go check prod, not a finish line.
How to catch it
Missed it? Here’s the fix — take it straight to your SOC.
Copy this to your detection team
The logic is public and every major SIEM already supports it. Here it is in Sigma, the open, vendor-neutral format your team can translate into whatever you run.
If your test came back silent, that rule is the whole fix. Drop it into your SIEM, or send your provider this page — “we ran this, nothing fired, here’s the detection.” Either way your coverage is better tonight than it was this morning. That’s the point.
A new one every week
This is technique 05 of many.
Each one is a real attacker move, a safe way to try it, and the detection to close the gap. Run them over a few weeks and you’ll learn more about your real coverage than any dashboard has told you.
Curious how a system catches all of these at once, out of the box? That’s what we build — meet Mobula →
Credit & sources
The technique and the incident are documented by MITRE ATT&CK (T1082) and the sources linked above. The detection is expressed in Sigma, the open detection format maintained by the SigmaHQ community, so any team can use it freely; its author is credited above under DRL 1.1.
We show you public attacker tradecraft and public detection logic, and hand you both. Nothing here reveals anything an attacker doesn’t already have — it just makes sure the defender has it too.
CYRAY · MOBULA — SECURITY OPERATIONS, ORCHESTRATED BY AI