Real-world descriptions of how a group, tool or campaign used a technique.
169 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1005 Data from Local System |
MalwareTrickBot | TrickBot collects local files and information from the victim’s local machine. |
| T1005 Data from Local System |
MalwareBLINDINGCAN | BLINDINGCAN has uploaded files from victim machines. |
| T1005 Data from Local System |
MalwareRCSession | RCSession can collect data from a compromised host. |
| T1005 Data from Local System |
MalwareQuietSieve | QuietSieve can collect files from a compromised host. |
| T1005 Data from Local System |
MalwareBumblebee | Bumblebee can capture and compress stolen credentials from the Registry and volume shadow copies. |
| T1005 Data from Local System |
MalwareBRICKSTORM | BRICKSTORM has commands that allow the actor download files from the compromised host to the C2 server, and to also download specific sections of a file. |
| T1005 Data from Local System |
MalwareAmadey | Amadey can collect information from a compromised host. |
| T1005 Data from Local System |
MalwareProxysvc | Proxysvc searches the local system and gathers data. |
| T1005 Data from Local System |
Malwareyty | yty collects files with the following extensions: .ppt, .pptx, .pdf, .doc, .docx, .xls, .xlsx, .docm, .rtf, .inp, .xlsm, .csv, .odt, .pps, .vcf and sends them back to the C2 server. |
| T1005 Data from Local System |
MalwareKOPILUWAK | KOPILUWAK can gather information from compromised hosts. |
| T1005 Data from Local System |
MalwareSardonic | Sardonic has the ability to collect data from a compromised machine to deliver to the attacker. |
| T1005 Data from Local System |
MalwareMisdat | Misdat has collected files and data from a compromised host. |
| T1005 Data from Local System |
MalwareUrsnif | Ursnif has collected files from victim machines, including certificates and cookies. |
| T1005 Data from Local System |
MalwareCASTLETAP | CASTLETAP can execute a C2 command to transfer files from victim machines. |
| T1005 Data from Local System |
MalwareThreatNeedle | ThreatNeedle can collect data and files from a compromised host. |
| T1005 Data from Local System |
MalwareHavoc | Havoc can download files from the victim's computer. |
| T1005 Data from Local System |
MalwareFrameworkPOS | FrameworkPOS can collect elements related to credit card data from process memory. |
| T1005 Data from Local System |
MalwareGravityRAT | GravityRAT steals files with the following extensions: .docx, .doc, .pptx, .ppt, .xlsx, .xls, .rtf, and .pdf. |
| T1005 Data from Local System |
MalwareInvisibleFerret | InvisibleFerret has collected data utilizing a script that contained a list of excluded files and directory names and naming patterns of interest such as environment and configuration files, documents, spreadsheets, and other files that contained the words secret, wallet, private, and password. |
| T1005 Data from Local System |
MalwareBankshot | Bankshot collects files from the local system. |
| T1005 Data from Local System |
MalwareSharpDisco | SharpDisco has dropped a recent-files stealer plugin to `C:\Users\Public\WinSrcNT\It11.exe`. |
| T1005 Data from Local System |
MalwarexCaon | xCaon has uploaded files from victims' machines. |
| T1005 Data from Local System |
MalwareNebulae | Nebulae has the capability to upload collected files to C2. |
| T1005 Data from Local System |
MalwareRainyDay | RainyDay can use a file exfiltration tool to collect recently changed files on a compromised host. |
| T1005 Data from Local System |
MalwareAppleSeed | AppleSeed can collect data on a compromised host. |
| T1005 Data from Local System |
MalwareTinyTurla | TinyTurla can upload files from a compromised host. |
| T1005 Data from Local System |
MalwareCosmicDuke | CosmicDuke steals user files from local hard drives with file extensions that match a predefined list. |
| T1005 Data from Local System |
MalwareEnvyScout | EnvyScout can collect sensitive NTLM material from a compromised host. |
| T1005 Data from Local System |
MalwareCrimson | Crimson can collect information from a compromised host. |
| T1005 Data from Local System |
MalwareTomiris | Tomiris has the ability to collect recent files matching a hardcoded list of extensions prior to exfiltration. |
| T1005 Data from Local System |
MalwareDUSTTRAP | DUSTTRAP can gather data from infected systems. |
| T1005 Data from Local System |
MalwareMachete | Machete searches the File system for files of interest. |
| T1005 Data from Local System |
MalwarePowerLess | PowerLess has the ability to exfiltrate data, including Chrome and Edge browser database files, from compromised machines. |
| T1005 Data from Local System |
MalwareAction RAT | Action RAT can collect local data from an infected machine. |
| T1005 Data from Local System |
MalwarePingPull | PingPull can collect data from a compromised host. |
| T1005 Data from Local System |
MalwareWellMess | WellMess can send files from the victim machine to C2. |
| T1005 Data from Local System |
MalwareWoody RAT | Woody RAT can collect information from a compromised host. |
| T1005 Data from Local System |
MalwareMafalda | Mafalda can collect files and information from a compromised host. |
| T1005 Data from Local System |
MalwareAuTo Stealer | AuTo Stealer can collect data such as PowerPoint files, Word documents, Excel files, PDF files, text files, database files, and image files from an infected machine. |
| T1005 Data from Local System |
MalwareSombRAT | SombRAT has collected data and files from a compromised host. |
| T1005 Data from Local System |
MalwareFLASHFLOOD | FLASHFLOOD searches for interesting files (either a default or customized set of file extensions) on the local system. FLASHFLOOD will scan the My Recent Documents, Desktop, Temporary Internet Files, and TEMP directories. FLASHFLOOD also collects information stored in the Windows Address Book. |
| T1005 Data from Local System |
MalwareFlawedAmmyy | FlawedAmmyy has collected information and files from a compromised machine. |
| T1005 Data from Local System |
MalwareLoFiSe | LoFiSe can collect files of interest from targeted systems. |
| T1005 Data from Local System |
MalwareMobileOrder | MobileOrder exfiltrates data collected from the victim mobile device. |
| T1005 Data from Local System |
MalwareInvisiMole | InvisiMole can collect data from the system, and can monitor changes in specified directories. |
| T1005 Data from Local System |
MalwareP.A.S. Webshell | P.A.S. Webshell has the ability to copy files on a compromised host. |
| T1005 Data from Local System |
MalwareNeoichor | Neoichor can upload files from a victim's machine. |
| T1005 Data from Local System |
MalwareMarkiRAT | MarkiRAT can upload data from the victim's machine to the C2 server. |
| T1005 Data from Local System |
MalwareKazuar | Kazuar uploads files from a specified directory to the C2 server. |
| T1005 Data from Local System |
MalwareCHIMNEYSWEEP | CHIMNEYSWEEP can collect files from compromised hosts. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.