MITRE ATT&CK technique
System Location Discovery detection rulesT1614
System Location Discovery (T1614) is a MITRE ATT&CK technique in the Discovery tactic. This page lists the 2 community-maintained Sigma detection rules in the library mapped to T1614 and its sub-techniques. Each rule includes its detection logic, log source, false positives and original YAML. These rules mainly target windows.
T1614 on attack.mitre.org2 rules
Console CodePage Lookup Via CHCP
mediumDetects use of chcp to look up the system locale value as part of host discovery
windows · process_creation
System Language Discovery via Reg.Exe
mediumDetects the usage of Reg.Exe to query system language settings. Attackers may discover the system language to determine the geographic location of victims, customize payloads for specific regions, or avoid targeting certain locales to evade detection.
windows · process_creation