System information discovery via psinfo.exe
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
6 Hours
Required Data
XDR Agent
ATT&CK Tactic
Discovery (TA0007)
ATT&CK Technique
System Information Discovery (T1082)
Severity
Low
Description
Using psinfo.exe, the attacker can gather information about the network, and gain an in-depth understanding of which devices are relevant to attack.
Attacker's Goals
Collect information about the host, network and user configuration for lateral movement and privilege escalation.
Investigative actions
Check whether the executing process is benign and if this was a desired behavior as part of its normal execution flow.
Verify that this isn't sanctioned IT activity.
Look for other hosts executing similar commands.
Was this helpful?
