T1614.001 System Language Discovery
Sub-technique of T1614 System Location Discovery
Adversaries may attempt to gather information about the system language of a victim in order to infer the geographical location of that host. This information may be used to shape follow-on behaviors, including whether the adversary infects the target and/or attempts specific actions. This decision may be employed by malware developers and operators to reduce their risk of attracting the…
Who uses it · with stories on Jábega
Sigma rules to hunt it
- Console CodePage Lookup Via CHCPmediumtest · windows
- System Language Discovery via Reg.Exemediumexperimental · windows
Rules from SigmaHQ · Detection Rule License 1.1. Technique from MITRE ATT&CK®.