description: "This playbook Remediates the System Information Discovery technique using intelligence-driven Courses of Action (COA) defined by Palo Alto Networks Unit 42 team.\n \n***Disclaimer: This playbook does not simulate an attack using the specified technique, but follows the steps to remediation as defined by Palo Alto Networks Unit 42 team’s Actionable Threat Objects and Mitigations (ATOMs).\nTechniques Handled:\n- T1082: System Information Discovery\n\nKill Chain phases:\n- Discovery\n\nMITRE ATT&CK Description:\n\nAn adversary may attempt to get detailed information about the operating system and hardware, including version, patches, hotfixes, service packs, and architecture. Adversaries may use the information from System Information Discovery during automated discovery to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions.\n\nTools such as Systeminfo can be used to gather detailed system information. A breakdown of system data can also be gathered through the macOS systemsetup command, but it requires administrative privileges.\n\nInfrastructure as a Service (IaaS) cloud providers such as AWS, GCP, and Azure allow access to instance and virtual machine information via APIs. Successful authenticated API calls can return data such as the operating system platform and status of a particular instance or the model view of a virtual machine.\n\nPossible playbook uses:\n- The playbook can be used independently to handle and remediate the specific technique.\n- The playbook can be used as a part of the “Courses of Action - Defense Evasion” playbook to remediate techniques based on the kill chain phase.\n- The playbook can be used as a part of the “MITRE ATT&CK - Courses of Action” playbook, which can be triggered by different sources and accepts the technique MITRE ATT&CK ID as an input." id: MITRE ATT&CK CoA - T1082 - System Information Discovery inputs: [] name: MITRE ATT&CK CoA - T1082 - System Information Discovery outputs: - contextPath: Handled.Techniques description: The techniques handled in this playbook type: unknown starttaskid: "0" tasks: "0": id: "0" ignoreworker: false nexttasks: '#none#': - "5" note: false quietmode: 0 separatecontext: false skipunavailable: false task: brand: "" id: 8e60441a-86eb-4c0b-84f4-3bde2619a537 iscommand: false name: "" version: -1 description: '' taskid: 8e60441a-86eb-4c0b-84f4-3bde2619a537 timertriggers: [] type: start view: |- { "position": { "x": 265, "y": -110 } } "1": id: "1" ignoreworker: false nexttasks: '#none#': - "6" note: false quietmode: 0 separatecontext: false skipunavailable: false task: brand: "" description: Cortex XDR monitors for behavioral events along a causality chain to identify discovery behaviors. id: 3f6e55d4-9036-473a-8222-d175d8303d44 iscommand: false name: Cortex XDR monitors for behavioral events along a causality chain to identify discovery behaviors type: regular version: -1 taskid: 3f6e55d4-9036-473a-8222-d175d8303d44 timertriggers: [] type: regular view: |- { "position": { "x": 265, "y": 540 } } "2": id: "2" ignoreworker: false note: false quietmode: 0 separatecontext: false skipunavailable: false task: brand: "" id: f0044a7f-a9ba-485e-8dc7-6f5589920c0a iscommand: false name: Done type: title version: -1 description: '' taskid: f0044a7f-a9ba-485e-8dc7-6f5589920c0a timertriggers: [] type: title view: |- { "position": { "x": 265, "y": 1105 } } "3": id: "3" ignoreworker: false nexttasks: '#default#': - "4" "yes": - "1" note: false quietmode: 0 scriptarguments: brandname: simple: Cortex XDR - IR separatecontext: false skipunavailable: false task: brand: "" description: Returns 'yes' if integration brand is available. Otherwise returns 'no' id: 423e30aa-9b91-422d-8e78-625a86b54b17 iscommand: false name: Is Cortex XDR integration Enabled? script: IsIntegrationAvailable type: condition version: -1 taskid: 423e30aa-9b91-422d-8e78-625a86b54b17 timertriggers: [] type: condition view: |- { "position": { "x": 265, "y": 195 } } "4": id: "4" ignoreworker: false nexttasks: '#none#': - "1" note: false quietmode: 0 separatecontext: false skipunavailable: false task: brand: "" description: | Enable the Cortex XDR integration to follow this CoA. If needed - please contact your Palo Alto Networks account manager for future guidance and assistance. id: 41184bd3-4ea5-4c0f-8990-f6b1bcaf2edc iscommand: false name: Manual - Enable Cortex XDR integration type: regular version: -1 taskid: 41184bd3-4ea5-4c0f-8990-f6b1bcaf2edc timertriggers: [] type: regular view: |- { "position": { "x": 520, "y": 370 } } "5": id: "5" ignoreworker: false nexttasks: '#none#': - "3" note: false quietmode: 0 separatecontext: false skipunavailable: false task: brand: "" id: 582019ae-12f5-4b29-823b-a79ef3543d00 iscommand: false name: Cortex XDR monitors for behavioral events along a causality chain to identify discovery behaviors type: title version: -1 description: '' taskid: 582019ae-12f5-4b29-823b-a79ef3543d00 timertriggers: [] type: title view: |- { "position": { "x": 265, "y": 50 } } "6": id: "6" ignoreworker: false nexttasks: '#none#': - "7" note: false quietmode: 0 scriptarguments: append: simple: "true" key: simple: Handled.Techniques stringify: {} value: simple: T1082 separatecontext: false skipunavailable: false task: brand: "" description: Set a value in context under the key you entered. id: b76e4762-1393-4f97-83ad-a97ed1b17706 iscommand: false name: Set technique handled script: Set type: regular version: -1 taskid: b76e4762-1393-4f97-83ad-a97ed1b17706 timertriggers: [] type: regular view: |- { "position": { "x": 265, "y": 720 } } "7": continueonerror: true id: "7" ignoreworker: false nexttasks: '#none#': - "2" note: false quietmode: 0 scriptarguments: columns: simple: technique context_path: simple: Handled.Techniques grid_id: simple: handledtechniques keys: {} overwrite: {} sort_by: {} unpack_nested_elements: {} separatecontext: false skipunavailable: false task: brand: "" description: Creates a Grid table from items or key-value pairs. id: 2a152e87-6784-4d28-8f5b-cab07e75aa35 iscommand: false name: Set grid field script: SetGridField type: regular version: -1 taskid: 2a152e87-6784-4d28-8f5b-cab07e75aa35 timertriggers: [] type: regular view: |- { "position": { "x": 265, "y": 910 } } version: -1 view: |- { "linkLabelsPosition": { "3_1_yes": 0.41 }, "paper": { "dimensions": { "height": 1280, "width": 635, "x": 265, "y": -110 } } } tests: - No tests (auto formatted) fromversion: 6.5.0