Technique.View on attack.mitre.org
Adversaries may search local system sources, such as file systems, configuration files, local databases, virtual machine files, or process memory, to find files of interest and sensitive data prior to Exfiltration.
Adversaries may do this using a Command and Scripting Interpreter, such as cmd as well as a Network Device CLI, which have functionality to interact with the file system to gather information. Adversaries may also use Automated Collection on the local system.
Rules on DetectionCode tagged with T1005.
| Rule | Level | Log source |
|---|---|---|
| OpenCanary - SMB File Open Request | high | opencanary / application |
| Script Interpreter Spawning Credential Scanner - Linux | high | linux / process_creation |
| Script Interpreter Spawning Credential Scanner - Windows | high | windows / process_creation |
| SQLite Chromium Profile Data DB Access | high | windows / process_creation |
| SQLite Firefox Profile Data DB Access | high | windows / process_creation |
| VeeamBackup Database Credentials Dump Via Sqlcmd.EXE | high | windows / process_creation |
| ADFS Database Named Pipe Connection By Uncommon Tool | medium | windows / pipe_created |
| Crash Dump Created By Operating System | medium | windows / NULL |
| Esentutl Steals Browser Information | medium | windows / process_creation |
| Veeam Backup Database Suspicious Query | medium | windows / process_creation |
| AWS EC2 VM Export Failure | low | aws / NULL |
| Cisco Collect Data | low | cisco / NULL |
| Rule | Type | Risk | Data source |
|---|---|---|---|
| Cisco ASA - Device File Copy Activity | Anomaly | NULL | Cisco ASA Logs |
| Cisco ASA - Device File Copy to Remote Location | Anomaly | NULL | Cisco ASA Logs |
| Cisco TFTP Server Configuration for Data Exfiltration | TTP | NULL | Cisco IOS Logs |
| ESXi Sensitive Files Accessed | TTP | NULL | VMWare ESXi Syslog |
| ESXi VM Exported via Remote Tool | TTP | NULL | VMWare ESXi Syslog |
| PTC Windchill Gateway Command Execution | Anomaly | NULL | Windchill Log4j |
| Sqlite Module In Temp Folder | TTP | NULL | Sysmon EventID 11 |
| Used by | Procedure example |
|---|---|
| GroupAgrius | Agrius gathered data from database and other critical servers in victim environments, then used wiping mechanisms as an anti-analysis and anti-forensics mechanism. |
| GroupAndariel | Andariel has collected large numbers of files from compromised network systems for later extraction. |
| GroupAPT1 | APT1 has collected files from a local victim. |
| GroupAPT28 | APT28 has retrieved internal documents from machines inside victim environments, including by using Forfiles to stage documents before exfiltration. |
| GroupAPT29 | APT29 has stolen data from compromised hosts. |
| GroupAPT3 | APT3 will identify Microsoft Office documents on the victim's computer. |
| GroupAPT37 | APT37 has collected data from victims' local systems. |
| GroupAPT38 | APT38 has collected data from a compromised host. |
| Used by | Procedure example |
|---|---|
| MalwareAction RAT | Action RAT can collect local data from an infected machine. |
| MalwareAmadey | Amadey can collect information from a compromised host. |
| MalwareAppleSeed | AppleSeed can collect data on a compromised host. |
| MalwareAuTo Stealer | AuTo Stealer can collect data such as PowerPoint files, Word documents, Excel files, PDF files, text files, database files, and image files from an infected machine. |
| MalwareBADFLICK | BADFLICK has uploaded files from victims' machines. |
| MalwareBADNEWS | When it first starts, BADNEWS crawls the victim's local drives and collects documents with the following extensions: .doc, .docx, .pdf, .ppt, .pptx, and .txt. |
| MalwareBadPatch | BadPatch collects files from the local system that have the following extensions, then prepares them for exfiltration: .xls, .xlsx, .pdf, .mdb, .rar, .zip, .doc, .docx. |
| MalwareBandook | Bandook can collect local files from the system . |
View all 169 software examples
| Used by | Procedure example |
|---|---|
| CampaignAnthropic AI-orchestrated Campaign | During the Anthropic AI-orchestrated Campaign, the adversary tasked Claude Code to automatically gather sensitive data stored within the local system to include credentials, system configurations and sensitive operational data. |
| CampaignC0015 | During C0015, the threat actors obtained files and data from the compromised network. |
| CampaignC0017 | During C0017, APT41 collected information related to compromised machines as well as Personal Identifiable Information (PII) from victim networks. |
| CampaignC0026 | During C0026, the threat actors collected documents from compromised hosts. |
| CampaignCostaRicto | During CostaRicto, the threat actors collected data and files from compromised networks. |
| CampaignCutting Edge | During Cutting Edge, threat actors stole the running configuration and cache data from targeted Ivanti Connect Secure VPNs. |
| CampaignFrankenstein | During Frankenstein, the threat actors used Empire to gather various local system information. |
| CampaignNight Dragon | During Night Dragon, the threat actors collected files and other data from compromised systems. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.