Data from Local System

T1005

Technique.View on attack.mitre.org

About this technique

Adversaries may search local system sources, such as file systems, configuration files, local databases, virtual machine files, or process memory, to find files of interest and sensitive data prior to Exfiltration.

Adversaries may do this using a Command and Scripting Interpreter, such as cmd as well as a Network Device CLI, which have functionality to interact with the file system to gather information. Adversaries may also use Automated Collection on the local system.

Detection rules19

Rules on DetectionCode tagged with T1005.

Sigma12

RuleLevelLog source
OpenCanary - SMB File Open Requesthighopencanary / application
Script Interpreter Spawning Credential Scanner - Linuxhighlinux / process_creation
Script Interpreter Spawning Credential Scanner - Windowshighwindows / process_creation
SQLite Chromium Profile Data DB Accesshighwindows / process_creation
SQLite Firefox Profile Data DB Accesshighwindows / process_creation
VeeamBackup Database Credentials Dump Via Sqlcmd.EXEhighwindows / process_creation
ADFS Database Named Pipe Connection By Uncommon Toolmediumwindows / pipe_created
Crash Dump Created By Operating Systemmediumwindows / NULL
Esentutl Steals Browser Informationmediumwindows / process_creation
Veeam Backup Database Suspicious Querymediumwindows / process_creation
AWS EC2 VM Export Failurelowaws / NULL
Cisco Collect Datalowcisco / NULL

Splunk7

RuleTypeRiskData source
Cisco ASA - Device File Copy ActivityAnomalyNULLCisco ASA Logs
Cisco ASA - Device File Copy to Remote LocationAnomalyNULLCisco ASA Logs
Cisco TFTP Server Configuration for Data ExfiltrationTTPNULLCisco IOS Logs
ESXi Sensitive Files AccessedTTPNULLVMWare ESXi Syslog
ESXi VM Exported via Remote ToolTTPNULLVMWare ESXi Syslog
PTC Windchill Gateway Command ExecutionAnomalyNULLWindchill Log4j
Sqlite Module In Temp FolderTTPNULLSysmon EventID 11

Groups46

Show 22 more

Software169

Show 145 more

Campaigns15

Procedure examples230

Groups46

Used byProcedure example
GroupAgrius

Agrius gathered data from database and other critical servers in victim environments, then used wiping mechanisms as an anti-analysis and anti-forensics mechanism.

GroupAndariel

Andariel has collected large numbers of files from compromised network systems for later extraction.

GroupAPT1

APT1 has collected files from a local victim.

GroupAPT28

APT28 has retrieved internal documents from machines inside victim environments, including by using Forfiles to stage documents before exfiltration.

GroupAPT29

APT29 has stolen data from compromised hosts.

GroupAPT3

APT3 will identify Microsoft Office documents on the victim's computer.

GroupAPT37

APT37 has collected data from victims' local systems.

GroupAPT38

APT38 has collected data from a compromised host.

View all 46 groups examples

Software169

Used byProcedure example
MalwareAction RAT

Action RAT can collect local data from an infected machine.

MalwareAmadey

Amadey can collect information from a compromised host.

MalwareAppleSeed

AppleSeed can collect data on a compromised host.

MalwareAuTo Stealer

AuTo Stealer can collect data such as PowerPoint files, Word documents, Excel files, PDF files, text files, database files, and image files from an infected machine.

MalwareBADFLICK

BADFLICK has uploaded files from victims' machines.

MalwareBADNEWS

When it first starts, BADNEWS crawls the victim's local drives and collects documents with the following extensions: .doc, .docx, .pdf, .ppt, .pptx, and .txt.

MalwareBadPatch

BadPatch collects files from the local system that have the following extensions, then prepares them for exfiltration: .xls, .xlsx, .pdf, .mdb, .rar, .zip, .doc, .docx.

MalwareBandook

Bandook can collect local files from the system .

View all 169 software examples

Campaigns15

Used byProcedure example
CampaignAnthropic AI-orchestrated Campaign

During the Anthropic AI-orchestrated Campaign, the adversary tasked Claude Code to automatically gather sensitive data stored within the local system to include credentials, system configurations and sensitive operational data.

CampaignC0015

During C0015, the threat actors obtained files and data from the compromised network.

CampaignC0017

During C0017, APT41 collected information related to compromised machines as well as Personal Identifiable Information (PII) from victim networks.

CampaignC0026

During C0026, the threat actors collected documents from compromised hosts.

CampaignCostaRicto

During CostaRicto, the threat actors collected data and files from compromised networks.

CampaignCutting Edge

During Cutting Edge, threat actors stole the running configuration and cache data from targeted Ivanti Connect Secure VPNs.

CampaignFrankenstein

During Frankenstein, the threat actors used Empire to gather various local system information.

CampaignNight Dragon

During Night Dragon, the threat actors collected files and other data from compromised systems.

View all 15 campaigns examples

References1

  1. show_run_config_cmd_cisco Open source
    Cisco. (2022, August 16). show running-config - Cisco IOS Configuration Fundamentals Command Reference . Retrieved July 13, 2022.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.