ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1005×

46 examples

TechniqueUsed byProcedure example
T1005
Data from Local System
GroupAPT38

APT38 has collected data from a compromised host.

T1005
Data from Local System
GroupGALLIUM

GALLIUM collected data from the victim's local system, including password hashes from the SAM hive in the Registry.

T1005
Data from Local System
GroupAPT3

APT3 will identify Microsoft Office documents on the victim's computer.

T1005
Data from Local System
GroupKimsuky

Kimsuky has collected Office, PDF, and HWP documents from its victims. Kimsuky has also harvested victim files through the use of the `RecentFiles()` function that collects paths of recently accessed files by parsing .lnk shortcuts from `%APPDATA%\Microsoft\Windows\Recent`.

T1005
Data from Local System
GroupVolt Typhoon

Volt Typhoon has stolen files from a sensitive file server and the Active Directory database from targeted environments, and used Wevtutil to extract event log information.

T1005
Data from Local System
GroupPatchwork

Patchwork collected and exfiltrated files from the infected system.

T1005
Data from Local System
GroupAPT41

APT41 has uploaded files and data from a compromised host.

T1005
Data from Local System
GroupDragonfly

Dragonfly has collected data from local victim systems.

T1005
Data from Local System
GroupmenuPass

menuPass has collected various files from the compromised computers.

T1005
Data from Local System
GroupHAFNIUM

HAFNIUM has collected data and files from a compromised machine.

T1005
Data from Local System
GroupFIN6

FIN6 has collected and exfiltrated payment card data from compromised systems.

T1005
Data from Local System
GroupGamaredon Group

Gamaredon Group has collected files from infected systems and uploaded them to a C2 server.

T1005
Data from Local System
GroupFIN7

FIN7 has collected files and other sensitive information from a compromised network.

T1005
Data from Local System
GroupSandworm Team

Sandworm Team has exfiltrated internal documents, files, and other data from compromised hosts.

T1005
Data from Local System
GroupAndariel

Andariel has collected large numbers of files from compromised network systems for later extraction.

T1005
Data from Local System
GroupCURIUM

CURIUM has exfiltrated data from a compromised machine.

T1005
Data from Local System
GroupAPT39

APT39 has used various tools to steal files from the compromised host.

T1005
Data from Local System
GroupAPT37

APT37 has collected data from victims' local systems.

T1005
Data from Local System
GroupOilRig

OilRig has used PowerShell to upload files from compromised systems.

T1005
Data from Local System
GroupWindigo

Windigo has used a script to gather credentials in files left on disk by OpenSSH backdoors.

T1005
Data from Local System
GroupAquatic Panda

Aquatic Panda captured local Windows security event log data from victim machines using the wevtutil utility to extract contents to an evtx output file.

T1005
Data from Local System
GroupKe3chang

Ke3chang gathered information and files from local directories for exfiltration.

T1005
Data from Local System
GroupAPT1

APT1 has collected files from a local victim.

T1005
Data from Local System
GroupTurla

Turla RPC backdoors can upload files from victim machines.

T1005
Data from Local System
GroupRedCurl

RedCurl has collected data from the local disk of compromised hosts.

T1005
Data from Local System
GroupStealth Falcon

Stealth Falcon malware gathers data from the local victim system.

T1005
Data from Local System
GroupAPT29

APT29 has stolen data from compromised hosts.

T1005
Data from Local System
GroupDark Caracal

Dark Caracal collected complete contents of the 'Pictures' folder from compromised Windows systems.

T1005
Data from Local System
GroupMirrorFace

MirrorFace gathered data and files of interest from victim's systems.

T1005
Data from Local System
GroupBRONZE BUTLER

BRONZE BUTLER has exfiltrated files stolen from local systems.

T1005
Data from Local System
GroupAxiom

Axiom has collected data from a compromised network.

T1005
Data from Local System
GroupEmber Bear

Ember Bear gathers victim system information such as enumerating the volume of a given device or extracting system and security event logs for analysis.

T1005
Data from Local System
GroupToddyCat

ToddyCat has run scripts to collect documents from targeted hosts.

T1005
Data from Local System
GroupLuminousMoth

LuminousMoth has collected files and data from compromised machines.

T1005
Data from Local System
GroupAgrius

Agrius gathered data from database and other critical servers in victim environments, then used wiping mechanisms as an anti-analysis and anti-forensics mechanism.

T1005
Data from Local System
GroupAPT28

APT28 has retrieved internal documents from machines inside victim environments, including by using Forfiles to stage documents before exfiltration.

T1005
Data from Local System
GroupFox Kitten

Fox Kitten has searched local system resources to access sensitive documents.

T1005
Data from Local System
GroupLazarus Group

Lazarus Group has collected data and files from compromised networks.

T1005
Data from Local System
GroupLAPSUS$

LAPSUS$ uploaded sensitive files, information, and credentials from a targeted organization for extortion or public release.

T1005
Data from Local System
GroupWizard Spider

Wizard Spider has collected data from a compromised host prior to exfiltration.

T1005
Data from Local System
GroupInception

Inception used a file hunting plugin to collect .txt, .pdf, .xls or .doc files from the infected host.

T1005
Data from Local System
GroupVOID MANTICORE

VOID MANTICORE has collected cached data and files from within the victim environment.

T1005
Data from Local System
GroupMagic Hound

Magic Hound has used a web shell to exfiltrate a ZIP file containing a dump of LSASS memory on a compromised machine.

T1005
Data from Local System
GroupThreat Group-3390

Threat Group-3390 ran a command to compile an archive of file types of interest from the victim user's directories.

T1005
Data from Local System
GroupFIN13

FIN13 has gathered stolen credentials, sensitive data such as point-of-sale (POS), and ATM data from a compromised network before exfiltration.

T1005
Data from Local System
GroupTeamPCP

TeamPCP has stolen source code from victim environments including Mistral AI.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.