Threadlinqs IntelligenceStart free

ATT&CK techniqueDiscovery

T1082 System Information Discovery

DiscoveryEnterprise

As of 2026-10-05, T1082 (System Information Discovery) appears in 1143 tracked threats, first reported 2021-11-25 and most recently 2026-10-03, with linked actors including APT38, Sapphire Sleet, TeamPCP; it most often appears alongside T1005 (Data from Local System).

Tracked threats
1143369 critical, 700 high, 68 medium, 2 low
First seen
2021-11-25
Last seen
2026-10-03
Threat actors
197In the threats using it
Detection rules
886Blue tier and above

Data as of:

Activity timeline

T1082 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 369 reports, and 1142 of the 1143 threats were reported in the twelve months to 2026-10.

How adversaries use it

T1082 System Information Discovery is catalogued by MITRE ATT&CK under the Discovery tactic in the Enterprise matrix. Threadlinqs maps 1143 of 2623 tracked threats (43.6%) to it; by severity that is 369 critical, 700 high, 68 medium, 2 low.

Threats that use T1082 most often also use T1005 Data from Local System (728 threats), T1027 Obfuscated Files or Information (707 threats), T1041 Exfiltration Over C2 Channel (599 threats), T1059 Command and Scripting Interpreter (593 threats), T1105 Ingress Tool Transfer (520 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

197 tracked threat actors appear in the threats that use T1082; the most frequent are APT38 (33), Sapphire Sleet (29), TeamPCP (28), Stardust Chollima (27), Lazarus Group (20).

Data sources

Telemetry that can reveal T1082, per MITRE ATT&CK.

  • Command — Command Execution
  • Process — OS API Execution, Process Creation

Threat actors using it

Tracked threats

The 30 most recent of 1143 tracked threats that use T1082.

Detection coverage

Threadlinqs maintains 886 detection rules mapped to T1082 (SPL 249, KQL 344, Sigma 293). Rule content is available to Blue tier accounts and above; this page shows counts only.

886 detection rules (SPL/KQL/Sigma) · Blue and above. Compare plans