{"id":"T1614","name":"System Location Discovery","url":"https://attack.mitre.org/techniques/T1614","tactics":["discovery"],"platforms":["IaaS","Linux","macOS","Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0043","stix_id":"x-mitre-detection-strategy--9daf5067-79c3-477c-bf41-813aada4770d","name":"Detection Strategy for System Location Discovery","url":"https://attack.mitre.org/detectionstrategies/DET0043","analytics":[{"id":"AN0119","stix_id":"x-mitre-analytic--cd4d2b49-6a27-41a7-ab20-d2a3791142bd","name":"Analytic 0119","description":"Unusual process or API usage attempting to query system locale, timezone, or keyboard layout (e.g., calls to GetLocaleInfoW, GetTimeZoneInformation). Detection can be enhanced by correlating with processes not typically associated with system configuration queries, such as unknown binaries or scripts.","url":"https://attack.mitre.org/detectionstrategies/DET0043#AN0119","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Security","channel":"EventCode=4688","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"wineventlog-security"},{"name":"etw:Microsoft-Windows-Kernel-Base","channel":"GetLocaleInfoW, GetTimeZoneInformation API calls","data_component":"DC0021","data_component_name":"OS API Execution","log_source_slug":"etw-microsoft-windows-kernel-base"}],"mutable_elements":[{"field":"ParentProcessAllowList","description":"Defines trusted processes expected to call locale APIs. Deviations may indicate adversarial activity."},{"field":"TimeWindow","description":"Specifies correlation window for API calls and suspicious process execution (e.g., 2m)."}],"live":true,"detection_strategies":["DET0043"],"techniques":["T1614"]},{"id":"AN0120","stix_id":"x-mitre-analytic--d053d033-b587-4ed0-bdbc-0c6a9bdd7c82","name":"Analytic 0120","description":"Detection of commands accessing locale, timezone, or language settings such as 'locale', 'timedatectl', or parsing /etc/timezone. Anomalous execution by unusual users or automation scripts should be flagged.","url":"https://attack.mitre.org/detectionstrategies/DET0043#AN0120","platforms":["Linux"],"log_source_references":[{"name":"auditd:SYSCALL","channel":"execve calls to locale, timedatectl, or cat /etc/timezone","data_component":"DC0064","data_component_name":"Command Execution","log_source_slug":"auditd-syscall"},{"name":"linux:Sysmon","channel":"EventCode=1","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"linux-sysmon"}],"mutable_elements":[{"field":"UserContext","description":"Unexpected users running location discovery commands may indicate malicious behavior."}],"live":true,"detection_strategies":["DET0043"],"techniques":["T1614"]},{"id":"AN0121","stix_id":"x-mitre-analytic--0521835b-bc02-41ed-8e6a-153e6422ee9c","name":"Analytic 0121","description":"Detection of system calls or commands accessing system locale (e.g., 'defaults read -g AppleLocale', 'systemsetup -gettimezone'). Correlate with unusual parent processes or execution contexts.","url":"https://attack.mitre.org/detectionstrategies/DET0043#AN0121","platforms":["macOS"],"log_source_references":[{"name":"macos:unifiedlog","channel":"defaults read -g AppleLocale, systemsetup -gettimezone","data_component":"DC0064","data_component_name":"Command Execution","log_source_slug":"macos-unifiedlog"},{"name":"macos:osquery","channel":"execve","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"macos-osquery"}],"mutable_elements":[{"field":"ExecutionPath","description":"Restrict known binaries allowed to query system locale on macOS."}],"live":true,"detection_strategies":["DET0043"],"techniques":["T1614"]},{"id":"AN0122","stix_id":"x-mitre-analytic--5b41efa6-7410-403b-ac07-89e262fa17ca","name":"Analytic 0122","description":"Detection of queries to instance metadata services (e.g., AWS IMDS, Azure Metadata Service) for availability zone, region, or network geolocation details. Correlation with non-management accounts or non-standard workloads may indicate adversary reconnaissance.","url":"https://attack.mitre.org/detectionstrategies/DET0043#AN0122","platforms":["IaaS"],"log_source_references":[{"name":"AWS:CloudTrail","channel":"GetMetadata, DescribeInstanceIdentity","data_component":"DC0021","data_component_name":"OS API Execution","log_source_slug":"aws-cloudtrail"},{"name":"azure:vpcflow","channel":"HTTP requests to 169.254.169.254 or Azure Metadata endpoints","data_component":"DC0085","data_component_name":"Network Traffic Content","log_source_slug":"azure-vpcflow"}],"mutable_elements":[{"field":"MetadataQueryAllowList","description":"Expected services that query cloud metadata APIs. Any additional sources may be malicious."}],"live":true,"detection_strategies":["DET0043"],"techniques":["T1614"]}],"live":true,"version":"1.0","techniques":["T1614"]}],"sigma_rules":[],"kev_cves":[],"_built":"2026-08-23 05:47 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}