System Information Discovery via dmidecode
Adversaries leverage the dmidecode utility on Linux hosts to perform hardware and system profiling, often using parent shells to execute collection commands for lateral movement and targeted exploitation.
Adversaries frequently use the Linux 'dmidecode' utility to harvest detailed system information, including hardware models, serial numbers, BIOS vendor details, and hypervisor identification. This activity is typically performed as part of an initial discovery phase to fingerprint a compromised host, allowing attackers to tailor their payload choices, identify virtualization environments, or plan lateral movement strategies.
The activity is often executed via a parent shell process (e.g., 'bash -c') to facilitate automated collection or integration into post-exploitation scripts. This pattern provides defenders with a clear signature for identifying suspicious discovery attempts, particularly when the execution occurs from non-interactive shells or correlates with other unauthorized post-exploitation actions. Defending against this requires monitoring for 'dmidecode' execution in conjunction with parent shell arguments that suggest automated profiling, such as '-c', and correlating these events with unusual user activity or subsequent data movement.
Attack Chain
- Attacker gains initial code execution on a Linux host via an exploited vulnerability or compromised service.
- Attacker drops a custom shell script or executes a one-liner using a standard system shell (e.g., /bin/bash).
- Attacker uses the parent shell with the '-c' argument to invoke 'dmidecode' to query specific DMI tables (e.g., -t system or -t bios).
- The output is collected into a variable or redirected to a temporary file (e.g., /tmp/dmi_out.txt).
- Attacker optionally compresses or encodes the collected system metadata using utilities like 'gzip' or 'base64'.
- The adversary exfiltrates the inventory file to external infrastructure via 'curl', 'scp', or similar network-capable utilities.
- Attacker uses the gathered system fingerprint to select specific post-exploitation tools or identify target-rich environments for further lateral movement.
Impact
Successful discovery allows attackers to map the internal network and hardware infrastructure of the victim organization. By identifying the underlying hypervisor or hardware model, adversaries can increase the efficacy of targeted exploits or bypass host-based security controls that are specific to certain configurations. Infiltration of enterprise environments often follows this profiling stage, potentially leading to widespread data exfiltration or ransomware deployment.
Recommendation
- Deploy the Sigma rule below to monitor for suspicious 'dmidecode' executions launched via parent shells.
- Monitor for unauthorized file writes in temporary directories such as /tmp, /var/tmp, and /dev/shm that correlate with 'dmidecode' process execution.
- Restrict 'dmidecode' execution to known administrative users or approved service accounts via sudoers and SELinux or AppArmor profiles.
- Audit network egress activity from shells or scripts that have recently performed system inventory tasks.
- Replace ad-hoc hardware inventory scripts with centrally managed, signed, and authorized configuration management tools.
Threat Hunt
Search for dmidecode executions from shell parents followed by network connections
Data: Process creation logs, Network connection logs
Mitigations
Restrict dmidecode execution via sudoers/AppArmor
T1082
Detection coverage 1
Detect Suspicious System Information Discovery via dmidecode
lowDetects dmidecode execution initiated from a shell with -c argument, a pattern commonly used for automated system profiling.
Detection queries are available on the platform. Get full rules →