216.73.216.36

T0888: Remote System Information Discovery

View on MITRE ATT&CK The MITRE Corporation · Published 13/04/2021 14:45 · Modified 27/03/2026 01:44

Essential information

MITRE technique ID
T0888
Confidence
100/100
Revoked
No
Published
13/04/2021 14:45
Modified
27/03/2026 01:44
Author / Source
The MITRE Corporation

Description

An adversary may attempt to get detailed information about remote systems and their peripherals, such as make/model, role, and configuration. Adversaries may use information from Remote System Information Discovery to aid in targeting and shaping follow-on behaviors. For example, the system's operational role and model information can dictate whether it is a relevant target for the adversary's operational objectives. In addition, the system's configuration may be used to scope subsequent technique usage. Requests for system information are typically implemented using automation and management protocols and are often automatically requested by vendor software during normal operation. This information may be used to tailor management actions, such as program download and system or module firmware. An adversary may leverage this same information by issuing calls directly to the system's API.

Kill chain phases

Kill chainPhase
mitre-ics-attack discovery

Marking (TLP)

Copyright 2015-2025, The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation.

External references