Skip to content
CIM-120 Cyber Incidents & Offender Methods

What is system discovery?

System discovery is activity used to learn about the device, operating system, software, configuration or environment in which access has been obtained.

Avoid the dangerous assumption

The dangerous assumption is that every system-information command is malicious.

It is not.

Administrators, support tools, installers and security products routinely gather the same information.

An offender may use system discovery to learn:

  • the device name
  • operating-system version
  • installed software
  • running processes
  • security tools
  • network configuration
  • user accounts
  • system architecture
  • available storage
  • virtualisation or cloud context.

The purpose is usually to understand what the system is, what access exists and what action may be possible next.

Investigators should preserve:

  • the command or tool used
  • the account context
  • the parent process
  • the time
  • the output where available
  • the system affected
  • the activity that followed.

A single command may be routine.

A sequence of discovery commands immediately after suspicious access may support a stronger inference of deliberate reconnaissance.

Do not assume that discovery proves privilege escalation, lateral movement or data theft followed.

It may show preparation, orientation or testing rather than completed harm.

Where legitimate administration is possible, compare the activity with change records, support tickets, scheduled tasks and the user’s normal role.

Where several discovery commands appear, identify whether the output from one command informed the next. That may support an interactive process rather than routine inventory, especially where the sequence changes in response to what the system reveals.

Operational takeaway

Treat system discovery as evidence of information gathering, and assess the command sequence, context and subsequent activity before describing it as malicious reconnaissance.

Keep moving

Where this question leads

These links explain why the next page may matter, rather than presenting an undifferentiated list.