{"id":"T1614.001","name":"System Language Discovery","url":"https://attack.mitre.org/techniques/T1614/001","tactics":["discovery"],"platforms":["Linux","macOS","Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0565","stix_id":"x-mitre-detection-strategy--9d3a5603-ae0e-41fe-b2f5-7f3e44c903d7","name":"Detection Strategy for System Language Discovery","url":"https://attack.mitre.org/detectionstrategies/DET0565","analytics":[{"id":"AN1561","stix_id":"x-mitre-analytic--b8685b0b-f96e-41a4-8e01-eec252756447","name":"Analytic 1561","description":"Registry access to system language keys (e.g., HKLM\\SYSTEM\\CurrentControlSet\\Control\\Nls\\Language) or suspicious processes invoking locale-related APIs (e.g., GetUserDefaultUILanguage, GetSystemDefaultUILanguage, GetKeyboardLayoutList). Defender visibility focuses on anomalous or non-standard processes issuing these queries, especially when run by unknown binaries or scripts.","url":"https://attack.mitre.org/detectionstrategies/DET0565#AN1561","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Security","channel":"EventCode=4657","data_component":"DC0050","data_component_name":"Windows Registry Key Access","log_source_slug":"wineventlog-security"},{"name":"WinEventLog:Sysmon","channel":"EventCode=1","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"wineventlog-sysmon"},{"name":"ETW","channel":"Calls to GetUserDefaultUILanguage, GetSystemDefaultUILanguage, GetKeyboardLayoutList","data_component":"DC0021","data_component_name":"OS API Execution","log_source_slug":"etw"}],"mutable_elements":[{"field":"ParentProcessAllowList","description":"Defines trusted processes allowed to query registry language keys or APIs. Unexpected parent-child process chains may indicate adversary use."},{"field":"QueryThreshold","description":"Frequency threshold for language registry or API calls within a set time window."}],"live":true,"detection_strategies":["DET0565"],"techniques":["T1614.001"]},{"id":"AN1562","stix_id":"x-mitre-analytic--c625c090-edcc-431a-a2fb-c31e4eb5f2cf","name":"Analytic 1562","description":"Processes executing commands to query system locale and language settings, such as 'locale', 'echo $LANG', or parsing environment variables. Suspicious activity is indicated by these commands being run by unusual users, automation scripts, or non-administrative processes.","url":"https://attack.mitre.org/detectionstrategies/DET0565#AN1562","platforms":["Linux"],"log_source_references":[{"name":"auditd:SYSCALL","channel":"execve calls to /usr/bin/locale or shell execution of $LANG","data_component":"DC0064","data_component_name":"Command Execution","log_source_slug":"auditd-syscall"},{"name":"linux:Sysmon","channel":"EventCode=1","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"linux-sysmon"}],"mutable_elements":[{"field":"UserContext","description":"Unexpected or non-admin users executing locale commands may suggest malicious behavior."}],"live":true,"detection_strategies":["DET0565"],"techniques":["T1614.001"]},{"id":"AN1563","stix_id":"x-mitre-analytic--ffc71b21-982b-4fc7-8276-bd679d67bc95","name":"Analytic 1563","description":"Execution of commands to query system locale and language settings, such as 'defaults read -g AppleLocale' or 'systemsetup -gettimezone'. Unusual parent processes or execution contexts of these commands may indicate adversarial discovery.","url":"https://attack.mitre.org/detectionstrategies/DET0565#AN1563","platforms":["macOS"],"log_source_references":[{"name":"macos:unifiedlog","channel":"defaults read -g AppleLocale or systemsetup -gettimezone","data_component":"DC0064","data_component_name":"Command Execution","log_source_slug":"macos-unifiedlog"},{"name":"macos:osquery","channel":"execve","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"macos-osquery"}],"mutable_elements":[{"field":"ExecutionPath","description":"Restrict or monitor processes outside of system utilities that query AppleLocale or system language settings."}],"live":true,"detection_strategies":["DET0565"],"techniques":["T1614.001"]}],"live":true,"version":"1.0","techniques":["T1614.001"]}],"sigma_rules":[{"id":"7090adee-82e2-4269-bd59-80691e7c6338","title":"Console CodePage Lookup Via CHCP","author":"_pete_0, TheDFIRReport","status":"test","level":"medium","date":"2022-02-21","modified":"2024-03-05","description":"Detects use of chcp to look up the system locale value as part of host discovery","references":["https://thedfirreport.com/2022/04/04/stolen-images-campaign-ends-in-conti-ransomware/","https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/chcp"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.discovery","attack.t1614.001"],"path":"rules/windows/process_creation/proc_creation_win_chcp_codepage_lookup.yml","techniques":["T1614.001"],"cves":[]},{"id":"c43a5405-e8e1-4221-9ac9-dbe3fa14e886","title":"System Language Discovery via Reg.Exe","author":"Marco Pedrinazzi (@pedrinazziM) (InTheCyber)","status":"experimental","level":"medium","date":"2026-01-09","modified":null,"description":"Detects the usage of Reg.Exe to query system language settings.\nAttackers may discover the system language to determine the geographic location of victims, customize payloads for specific regions,\nor avoid targeting certain locales to evade detection.\n","references":["https://scythe.io/threat-thursday/threatthursday-darkside-ransomware"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.discovery","attack.t1614.001"],"path":"rules/windows/process_creation/proc_creation_win_reg_system_language_discovery.yml","techniques":["T1614.001"],"cves":[]}],"kev_cves":[],"_built":"2026-08-23 05:47 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}