An adversary may attempt to get detailed information about remote systems and their peripherals, such as make/model, role, and configuration. Adversaries may use information from Remote System Information Discovery to aid in targeting and shaping follow-on behaviors. For example, the system's operational role and model information can dictate whether it is a relevant target for the adversary's operational objectives. In addition, the system's configuration may be used to scope subsequent technique usage. Requests for system information are typically implemented using automation and management protocols and are often automatically requested by vendor software during normal operation. This information may be used to tailor management actions, such as program download and system or module firmware. An adversary may leverage this same information by issuing calls directly to the system's API.

Linked Issues

Issuelinks
Linktype Issue
is related to Techniques
is related to Remote Terminal Unit (RTU)
is related to Intelligent Electronic Device (IED)
is related to Jump Host
is related to Programmable Logic Controller (PLC)
is related to Human-Machine Interface (HMI)
is related to Application Server
is related to Switch
is related to Data Gateway
is related to Workstation
is related to Distributed Control System (DCS) Controller
is related to Control Server
is related to Field I/O
is related to Virtual Private Network (VPN) Server
is related to Safety Controller
is related to Programmable Automation Controller (PAC)
is related to Data Historian
is related to Firewall
is blocked by Static Network Configuration
is blocked by Detection of Remote System Information Discovery
Impressum German English