Gold Open Source
ExplorePackagesVulnerabilitiesCWEsMCP ServersScan
Login
Gold Open Source

The authoritative source for production-ready open-source components. Every package, container image, AI model, and MCP server undergoes rigorous verification for security, malware, and license compliance.

Explore Gold

  • Explore Everything
  • Packages
  • Gold Certified Packages
  • Container Images
  • AI Models
  • MCP Servers
  • Agent Skills
  • Chip Manufacturers

Security Data & Tools

  • Scan Your Dependencies
  • Trending Threats
  • Threat RSS Feeds
  • CVE Database
  • Actively Exploited (KEV)
  • SGZ Zero-Days
  • CWE Index
  • MITRE ATT&CK
  • Malicious Packages
  • Security Glossary
  • Supply-Chain Report
  • Developers (API & Badge)
  • Chrome Extension
  • Credits & Data Sources

Products

  • The Platform
  • ESSCM
  • Portal
  • TPRM
  • OSM
  • Cowork
  • Code / Runner
  • Guard

Use Cases

  • Know Your Software
  • Auto-Fix Vulnerabilities
  • Asset Discovery
  • AI Governance
  • MCP Server Security
  • Supply Chain Compliance
  • Zero-Day Discovery
  • All Use Cases

Company

  • About
  • Pricing
  • Blog
  • Documentation
  • Safeguard Academy
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 Gold Open Source. All rights reserved.

Built with care bySafeguard
Home/ATT&CK/T1426
MITRE ATT&CK Technique

T1426: System Information Discovery

ShareXLinkedInRedditHN

Adversaries may attempt to get detailed information about a device’s operating system and hardware, including versions, patches, and architecture. Adversaries may use the information from [System Information Discovery](https://attack.mitre.org/techniques/T1426) during automated discovery to shape follow-on behaviors, including whether or not to fully infects the target and/or attempts specific actions. On Android, much of this information is programmatically accessible to applications through the `android.os.Build` class. (Citation: Android-Build) iOS is much more restrictive with what information is visible to applications. Typically, applications will only be able to query the device model and which version of iOS it is running.

Tactics
Discovery
Platforms
Android, iOS

▪Used by groups (1)

G0112Windshift

▪Software using this technique (55)

S0288KeyRaidermalwareS0289Pegasus for iOSmalwareS0304Android/Chuli.AmalwareS0310ANDROIDOS_ANSERVER.AmalwareS0311YiSpectermalwareS0313RuMMSmalwareS0318XLoader for AndroidmalwareS0326RedDropmalwareS0399PallasmalwareS0403RiltokmalwareS0406GustuffmalwareS0407MonoklemalwareS0411RotexymalwareS0418ViceLeakermalwareS0420DvmapmalwareS0421GolfSpymalwareS0422AnubismalwareS0425Corona UpdatesmalwareS0427TrickMomalwareS0463INSOMNIAmalwareS0478EventBotmalwareS0480CerberusmalwareS0485MandrakemalwareS0490XLoader for iOSmalwareS0505Desert ScorpionmalwareS0506ViperRATmalwareS0507eSurvmalwareS0509FakeSpymalwareS0522ExobotmalwareS0525Android/AdDisplay.AshasmalwareS0529CarbonStealmalwareS0535Golden CupmalwareS0536GPlayedmalwareS0540AsacubmalwareS0544HenBoxmalwareS0550DoubleAgentmalwareS0551GoldenEaglemalwareS0555CHEMISTGAMESmalwareS0558Tiktok PromalwareS0577FrozenCellmalwareS1056TianySpymalwareS1061AbstractEmumalwareS1062S.O.V.A.malwareS1077HornbillmalwareS1079BOULDSPYmalwareS1082SunbirdmalwareS1083ChameleonmalwareS1094BRATAmalwareS1095AhRatmalwareS1126PhenakitemalwareS1185LightSpymalwareS1231GodFathermalwareS1241RatMiladmalwareS9005DocSwapmalwareS9006VajraSpymalware

▪Reference

T1426on MITRE ATT&CK

MITRE ATT&CK® is a registered trademark of The MITRE Corporation. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.