Skip to content
Skip to main content
Cyber Incidents & Offender Methods Foundation Explainer

What is system discovery?

System discovery is simply a computer answering questions about itself.

Someone using a Windows machine might ask for the computer name, the logged-on user, the operating-system version, running processes or network settings. None of those things is especially exotic on its own. The value comes from seeing what was asked, what came back, and what happened next.

That can tell you how somebody found their bearings on a machine before moving on to something more specific.

What does it look like?

A few ordinary Windows commands make the idea clear:

Command What it tells you Example result
hostname What this computer is called FIN-LAP-07
systeminfo What sort of system this is Windows version, build, architecture
whoami Which account is in use northstar\jpatel
tasklist What is running Processes and process IDs
ipconfig /all How the computer is connected IP address, DNS, gateway and interfaces

The commands matter less than the answers.

If hostname returns FIN-LAP-07, whoami returns an account name and ipconfig /all shows the local network, the person or process now knows a lot more about the machine than they did a minute earlier.

That naturally leads into network discovery, account discovery, permission and group discovery or security-software discovery, depending on what appears.

Where might you see the evidence?

You may never see somebody sitting at a command prompt. More often, you are working backwards from records left behind.

Useful places to look include:

  • endpoint or EDR process records;
  • command or PowerShell history;
  • Windows process-creation events where enabled;
  • remote-access or management-session logs;
  • files containing redirected command output; and
  • later authentication, network or file activity involving something that was just discovered.

A process record can be particularly useful:

Simplified endpoint process record
2026-09-18T10:14:03Z   device=FIN-LAP-07   user=northstar\jpatelparent=cmd.exe   process=hostname.exe   result=FIN-LAP-07

That gives you the device, account, process relationship, time and result in one place.

Now imagine the same session goes on to reveal a backup account and then another internal server. Suddenly those early commands are no longer just background noise — they help explain how the later target came into view.

What is worth preserving?

If system discovery matters to the incident, try to keep enough context to answer:

  • Which device was involved?
  • Which account or session was using it?
  • What process or command ran?
  • What result came back?
  • What happened immediately before and after?

That is usually much more useful than recording a command name on its own.

And remember: administrators and support tools ask many of the same questions. If that is a realistic explanation in the environment, legitimate administration and reconnaissance is the next comparison to make.

The practical takeaway is simple: system discovery shows how somebody learned what kind of machine they were on and what it could tell them next.

Reference: CIM-120Cyber Incidents & Offender Methods