{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/profiling/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":[],"_cs_severities":["low"],"_cs_tags":["discovery","linux","profiling"],"_cs_type":"advisory","_cs_vendors":[],"content_html":"\u003cp\u003eAdversaries frequently use the Linux 'dmidecode' utility to harvest detailed system information, including hardware models, serial numbers, BIOS vendor details, and hypervisor identification. This activity is typically performed as part of an initial discovery phase to fingerprint a compromised host, allowing attackers to tailor their payload choices, identify virtualization environments, or plan lateral movement strategies.\u003c/p\u003e\n\u003cp\u003eThe activity is often executed via a parent shell process (e.g., 'bash -c') to facilitate automated collection or integration into post-exploitation scripts. This pattern provides defenders with a clear signature for identifying suspicious discovery attempts, particularly when the execution occurs from non-interactive shells or correlates with other unauthorized post-exploitation actions. Defending against this requires monitoring for 'dmidecode' execution in conjunction with parent shell arguments that suggest automated profiling, such as '-c', and correlating these events with unusual user activity or subsequent data movement.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker gains initial code execution on a Linux host via an exploited vulnerability or compromised service.\u003c/li\u003e\n\u003cli\u003eAttacker drops a custom shell script or executes a one-liner using a standard system shell (e.g., /bin/bash).\u003c/li\u003e\n\u003cli\u003eAttacker uses the parent shell with the '-c' argument to invoke 'dmidecode' to query specific DMI tables (e.g., -t system or -t bios).\u003c/li\u003e\n\u003cli\u003eThe output is collected into a variable or redirected to a temporary file (e.g., /tmp/dmi_out.txt).\u003c/li\u003e\n\u003cli\u003eAttacker optionally compresses or encodes the collected system metadata using utilities like 'gzip' or 'base64'.\u003c/li\u003e\n\u003cli\u003eThe adversary exfiltrates the inventory file to external infrastructure via 'curl', 'scp', or similar network-capable utilities.\u003c/li\u003e\n\u003cli\u003eAttacker uses the gathered system fingerprint to select specific post-exploitation tools or identify target-rich environments for further lateral movement.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful discovery allows attackers to map the internal network and hardware infrastructure of the victim organization. By identifying the underlying hypervisor or hardware model, adversaries can increase the efficacy of targeted exploits or bypass host-based security controls that are specific to certain configurations. Infiltration of enterprise environments often follows this profiling stage, potentially leading to widespread data exfiltration or ransomware deployment.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eDeploy the Sigma rule below to monitor for suspicious 'dmidecode' executions launched via parent shells.\u003c/li\u003e\n\u003cli\u003eMonitor for unauthorized file writes in temporary directories such as /tmp, /var/tmp, and /dev/shm that correlate with 'dmidecode' process execution.\u003c/li\u003e\n\u003cli\u003eRestrict 'dmidecode' execution to known administrative users or approved service accounts via sudoers and SELinux or AppArmor profiles.\u003c/li\u003e\n\u003cli\u003eAudit network egress activity from shells or scripts that have recently performed system inventory tasks.\u003c/li\u003e\n\u003cli\u003eReplace ad-hoc hardware inventory scripts with centrally managed, signed, and authorized configuration management tools.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-10-08T19:06:37Z","date_published":"2026-10-08T19:06:37Z","id":"https://feed.craftedsignal.io/briefs/2026-10-linux-dmidecode-discovery/","summary":"Adversaries leverage the dmidecode utility on Linux hosts to perform hardware and system profiling, often using parent shells to execute collection commands for lateral movement and targeted exploitation.","title":"System Information Discovery via dmidecode","url":"https://feed.craftedsignal.io/briefs/2026-10-linux-dmidecode-discovery/"}],"language":"en","title":"CraftedSignal Threat Feed - Profiling","version":"https://jsonfeed.org/version/1.1"}