What is system discovery?¶
System discovery is simply a computer answering questions about itself.
Someone using a Windows machine might ask for the computer name, the logged-on user, the operating-system version, running processes or network settings. None of those things is especially exotic on its own. The value comes from seeing what was asked, what came back, and what happened next.
That can tell you how somebody found their bearings on a machine before moving on to something more specific.
What does it look like?¶
A few ordinary Windows commands make the idea clear:
| Command | What it tells you | Example result |
|---|---|---|
hostname | What this computer is called | FIN-LAP-07 |
systeminfo | What sort of system this is | Windows version, build, architecture |
whoami | Which account is in use | northstar\jpatel |
tasklist | What is running | Processes and process IDs |
ipconfig /all | How the computer is connected | IP address, DNS, gateway and interfaces |
The commands matter less than the answers.
If hostname returns FIN-LAP-07, whoami returns an account name and ipconfig /all shows the local network, the person or process now knows a lot more about the machine than they did a minute earlier.
The answers can become the starting point for account, network, service or security discovery.
That naturally leads into network discovery, account discovery, permission and group discovery or security-software discovery, depending on what appears.
Where might you see the evidence?¶
You may never see somebody sitting at a command prompt. More often, you are working backwards from records left behind.
Useful places to look include:
- endpoint or EDR process records;
- command or PowerShell history;
- Windows process-creation events where enabled;
- remote-access or management-session logs;
- files containing redirected command output; and
- later authentication, network or file activity involving something that was just discovered.
A process record can be particularly useful:
That gives you the device, account, process relationship, time and result in one place.
Now imagine the same session goes on to reveal a backup account and then another internal server. Suddenly those early commands are no longer just background noise — they help explain how the later target came into view.
What is worth preserving?¶
If system discovery matters to the incident, try to keep enough context to answer:
- Which device was involved?
- Which account or session was using it?
- What process or command ran?
- What result came back?
- What happened immediately before and after?
That is usually much more useful than recording a command name on its own.
And remember: administrators and support tools ask many of the same questions. If that is a realistic explanation in the environment, legitimate administration and reconnaissance is the next comparison to make.
The practical takeaway is simple: system discovery shows how somebody learned what kind of machine they were on and what it could tell them next.