Linux System & Hardware Information Discovery via File and Version Reads
Detects Linux file access to BIOS/DMI, hardware model, kernel, and OS release/issue identifiers used for system profiling.
- Product
- linux
- Service
- auditd
- Author
- Ömer Günal, oscd.community (SigmaHQ), DRL 1.1
- Published
- 2020-10-08
- Updated
- 2026-07-31
ATT&CK techniques
DiscoveryRecon
Resource Dev
Initial Access
Execution
Persistence
Priv Esc
Defense Evasion
Cred Access
Discovery
Lateral Movement
Collection
C2
Exfiltration
Impact
What it detects
This rule flags process activity that directly reads common Linux system and hardware identification files and version/release indicators. Attackers often use these artifacts to fingerprint the environment, tailor follow-on behavior, or decide whether specific software or hardware paths are present. It relies on Linux auditd telemetry that records the process path access events matching the specific file patterns listed.
Reporting behind it
Changelog
v3- v3Candidate ingested via manual entry.2026-07-31
- v2Candidate ingested via manual entry.2026-07-31
- v1No changelog recorded for this version.2026-07-30
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.
title: Linux System & Hardware Information Discovery via File and Version Reads
id: 5c145078-1848-4604-b05b-cd812a97ec17
related:
- id: 42df45e7-e6e9-43b5-8f26-bec5b39cc239
type: derived
- id: 1f358e2e-cb63-43c3-b575-dfb072a6814f
type: derived
status: stable
description: This rule flags process activity that directly reads common Linux system and hardware identification files and version/release indicators. Attackers often use these artifacts to fingerprint the environment, tailor follow-on behavior, or decide whether specific software or hardware paths are present. It relies on Linux auditd telemetry that records the process path access events matching the specific file patterns listed.
references:
- https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1082/T1082.md#atomic-test-4---linux-vm-check-via-hardware
- https://github.com/SigmaHQ/sigma/blob/master/rules/linux/auditd/path/lnx_auditd_system_info_discovery2.yml
author: Ömer Günal, oscd.community, Huntrule Team
date: 2020-10-08
modified: 2022-11-26
tags:
- attack.discovery
- attack.t1082
logsource:
product: linux
service: auditd
detection:
selection:
type: PATH
name:
- /sys/class/dmi/id/bios_version
- /sys/class/dmi/id/product_name
- /sys/class/dmi/id/chassis_vendor
- /proc/scsi/scsi
- /proc/ide/hd0/model
- /proc/version
- /etc/*version
- /etc/*release
- /etc/issue
condition: selection
falsepositives:
- Legitimate administration activities
level: informational
license: DRL-1.1