Real-world descriptions of how a group, tool or campaign used a technique.
15 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1005 Data from Local System |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group used malicious Trojans and DLL files to exfiltrate data from an infected host. |
| T1005 Data from Local System |
CampaignSharePoint ToolShell Exploitation | During SharePoint ToolShell Exploitation, threat actors extracted information from the compromised systems. |
| T1005 Data from Local System |
CampaignFrankenstein | During Frankenstein, the threat actors used Empire to gather various local system information. |
| T1005 Data from Local System |
CampaignOperation Honeybee | During Operation Honeybee, the threat actors collected data from compromised hosts. |
| T1005 Data from Local System |
CampaignOperation MidnightEclipse | During Operation MidnightEclipse, threat actors stole saved cookies and login data from targeted systems. |
| T1005 Data from Local System |
CampaignCutting Edge | During Cutting Edge, threat actors stole the running configuration and cache data from targeted Ivanti Connect Secure VPNs. |
| T1005 Data from Local System |
CampaignAnthropic AI-orchestrated Campaign | During the Anthropic AI-orchestrated Campaign, the adversary tasked Claude Code to automatically gather sensitive data stored within the local system to include credentials, system configurations and sensitive operational data. |
| T1005 Data from Local System |
CampaignC0015 | During C0015, the threat actors obtained files and data from the compromised network. |
| T1005 Data from Local System |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 extracted files from compromised networks. |
| T1005 Data from Local System |
CampaignOperation CuckooBees | During Operation CuckooBees, the threat actors collected data, files, and other information from compromised networks. |
| T1005 Data from Local System |
CampaignNight Dragon | During Night Dragon, the threat actors collected files and other data from compromised systems. |
| T1005 Data from Local System |
CampaignOperation Wocao | During Operation Wocao, threat actors exfiltrated files and directories of interest from the targeted system. |
| T1005 Data from Local System |
CampaignC0017 | During C0017, APT41 collected information related to compromised machines as well as Personal Identifiable Information (PII) from victim networks. |
| T1005 Data from Local System |
CampaignC0026 | During C0026, the threat actors collected documents from compromised hosts. |
| T1005 Data from Local System |
CampaignCostaRicto | During CostaRicto, the threat actors collected data and files from compromised networks. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.