T0888: Remote System Information Discovery
Essential information
- MITRE technique ID
T0888- Confidence
- 100/100
- Revoked
- No
- Published
- 13/04/2021 14:45
- Modified
- 27/03/2026 01:44
- Author / Source
- The MITRE Corporation
Description
An adversary may attempt to get detailed information about remote systems and their peripherals, such as make/model, role, and configuration. Adversaries may use information from Remote System Information Discovery to aid in targeting and shaping follow-on behaviors. For example, the system's operational role and model information can dictate whether it is a relevant target for the adversary's operational objectives. In addition, the system's configuration may be used to scope subsequent technique usage.
Requests for system information are typically implemented using automation and management protocols and are often automatically requested by vendor software during normal operation. This information may be used to tailor management actions, such as program download and system or module firmware. An adversary may leverage this same information by issuing calls directly to the system's API.
Kill chain phases
| Kill chain | Phase |
|---|---|
| mitre-ics-attack | discovery |
Marking (TLP)
Copyright 2015-2025, The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation.