Test your SOC · about a minute

Can your SOC see the machine being sized up?

One real attacker move, a safe way to run it on a machine you own, and the detection that closes the gap — in that order, so you leave with better coverage than you arrived with.

technique T1082 · System Information Discoveryseen in Black Bastawhere any Windows box

What this is about

Can your SOC see an attacker taking inventory?

Before an intruder decides what to do with a machine, they ask it what it is. systeminfo answers in one screen: the Windows build, the domain, the patch level, the memory, the boot time. It is the same command a help-desk engineer runs, and it is the first thing a hands-on attacker runs after landing.

The detection does not try to ban the tool — plenty of legitimate work needs it. It watches for the execution, so that when a box is inventoried by something that has no reason to inventory it, a human gets to look at the timing and the parent process.

The detection watches one thing: the built-in systeminfo tool being run to read the machine's full specification.

This is not hypothetical

The Black Basta ransomware operation is documented performing system information discovery on machines it reaches. Knowing the build and the patch level tells the operator which privilege-escalation path is likely to work; knowing the memory and the role tells them whether this box is worth encrypting or worth keeping quiet.

There is no malware in this step and nothing to quarantine. It is one built-in command, run by an ordinary account — the same line you are about to run yourself.

The actor above is named in MITRE ATT&CK’s own Procedure Examples for this technique; the link is where you can read it. Nothing on this page discloses a move an attacker does not already have — it just makes sure the defender has it too.

One command, the whole machine

Build, domain, hotfixes, memory, uptime. An attacker learns in a second what would take them an hour of poking around.

Nothing to block

systeminfo ships with Windows and your own staff use it. The signal is who ran it, from what, and when — never the file itself.

It comes before the decision

The inventory is how an intruder picks the escalation path and the target. Catching it buys you the time before they act.

The test

Run the real thing. Safely. On a box you own.

Run the same inventory an intruder runs, then open your own alerts.

01

Take the inventory

Run systeminfo — the built-in that prints the machine's full specification in one go. This is the moment your SOC should notice.

02

Read what it told you

Look at the output the way an attacker would: build number, domain membership, installed hotfixes. That is the map they just got for free.

03

Check your alerts

Open your SOC or EDR. Did system information discovery fire — or was the machine sized up in silence?

test-your-soc-system-info.ps1 · PowerShell · a machine you own
# test-your-soc-system-info.ps1 — run on a machine you own.
# Safe: one read-only lookup. Nothing is created, changed or deleted.
# STEP 1 - the inventory an intruder takes the minute they land.
systeminfo
# STEP 2 - open your SOC / EDR. Did system information discovery alert?

One read-only command that prints the machine's own specification. Nothing is created, changed or deleted, so there is nothing to undo and no admin rights are needed.

Reading the result — honestly

Something fired

Your tooling watches for machines being inventoried

Good — an intruder sizing up a box would surface the same way. On to the next one.

Silence

The inventory passed unseen — now you know

Not a verdict on your team; a specific, fixable gap you just found in a minute. The detection below is exactly what to hand them to close it.

Straight with you: we never see your alerts — you’re the judge, which is also why we never touch your data. And a lab isn’t production; a test box often logs differently than the real fleet. "It fired" means your EDR flagged systeminfo running — note that a lone run is often legitimate, so the valuable catch is systeminfo launched by an unexpected parent, or alongside other discovery commands in the same minute. Treat a pass as a reason to go check prod, not a finish line.

How to catch it

Missed it? Here’s the fix — take it straight to your SOC.

The logic is public and every major SIEM already supports it. Here it is in Sigma, the open, vendor-neutral format your team can translate into whatever you run.

proc_creation_win_systeminfo_execution.yml
title: Suspicious Execution of Systeminfo
id: 0ef56343-059e-4cb6-adc1-4c3c967c5e46
status: test
description: Detects usage of the "systeminfo" command to retrieve information
references:
    - https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1082/T1082.md#atomic-test-1---system-information-discovery
    - https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/systeminfo
author: frack113
date: 2022-01-01
modified: 2022-07-14
tags:
    - attack.discovery
    - attack.t1082
logsource:
    category: process_creation
    product: windows
detection:
    selection:
        - Image|endswith: '\systeminfo.exe'
        - OriginalFileName: 'sysinfo.exe'
    condition: selection
falsepositives:
    - Unknown
level: low

Suspicious Execution of Systeminfo · SigmaHQ rule 0ef56343-059e-4cb6-adc1-4c3c967c5e46

Author frack113 · quoted in full and unmodified under the Detection Rule License 1.1 (DRL 1.1)

https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_systeminfo_execution.yml

Retrieved 2026-09-11 · file sha256 932bbd8e70ad177d6de617aee50942dec1264453e89dcd3ca84aca65c771920f

If your test came back silent, that rule is the whole fix. Drop it into your SIEM, or send your provider this page — “we ran this, nothing fired, here’s the detection.” Either way your coverage is better tonight than it was this morning. That’s the point.

A new one every week

This is technique 05 of many.

Each one is a real attacker move, a safe way to try it, and the detection to close the gap. Run them over a few weeks and you’ll learn more about your real coverage than any dashboard has told you.

Curious how a system catches all of these at once, out of the box? That’s what we build — meet Mobula →

Credit & sources

The technique and the incident are documented by MITRE ATT&CK (T1082) and the sources linked above. The detection is expressed in Sigma, the open detection format maintained by the SigmaHQ community, so any team can use it freely; its author is credited above under DRL 1.1.

We show you public attacker tradecraft and public detection logic, and hand you both. Nothing here reveals anything an attacker doesn’t already have — it just makes sure the defender has it too.

CYRAY · MOBULA — SECURITY OPERATIONS, ORCHESTRATED BY AI