Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1005 Data from Local System |
MalwarePillowmint | Pillowmint has collected credit card data using native API functions. |
| T1005 Data from Local System |
MalwareMacMa | MacMa can collect then exfiltrate files from the compromised system. |
| T1005 Data from Local System |
MalwareFunnyDream | FunnyDream can upload files from victims' machines. |
| T1005 Data from Local System |
MalwareSysUpdate | SysUpdate can collect information and files from a compromised host. |
| T1005 Data from Local System |
MalwareOutSteel | OutSteel can collect information from a compromised host. |
| T1005 Data from Local System |
MalwarePUNCHTRACK | PUNCHTRACK scrapes memory for properly formatted payment card data. |
| T1005 Data from Local System |
MalwareLAMEHUG | LAMEHUG has the ability to collect system information and files of interest from compromised systems. |
| T1005 Data from Local System |
MalwareGrimAgent | GrimAgent can collect data and files from a compromised host. |
| T1005 Data from Local System |
MalwareStealBit | StealBit can upload data and files to the LockBit victim-shaming site. |
| T1005 Data from Local System |
MalwareZxShell | ZxShell can transfer files from a compromised host. |
| T1005 Data from Local System |
MalwareSLIGHTPULSE | SLIGHTPULSE can read files specified on the local system. |
| T1005 Data from Local System |
MalwareSPAWNCHIMERA | SPAWNCHIMERA has extracted the device’s Linux kernel image (vmlinux). |
| T1005 Data from Local System |
MalwareTroll Stealer | Troll Stealer gathers information from infected systems such as SSH information from the victim's `.ssh` directory. Troll Stealer collects information from local FileZilla installations and Microsoft Sticky Note. |
| T1005 Data from Local System |
MalwarenjRAT | njRAT can collect data from a local system. |
| T1005 Data from Local System |
MalwareIceApple | IceApple can collect files, passwords, and other data from a compromised host. |
| T1005 Data from Local System |
MalwaremetaMain | metaMain can collect files and system information from a compromised host. |
| T1005 Data from Local System |
MalwareSideTwist | SideTwist has the ability to upload files from a compromised host. |
| T1005 Data from Local System |
MalwareMis-Type | Mis-Type has collected files and data from a compromised host. |
| T1005 Data from Local System |
MalwareXCSSET | XCSSET collects contacts and application data from files in Desktop, Documents, Downloads, Dropbox, and WeChat folders. |
| T1005 Data from Local System |
MalwareOctopus | Octopus can exfiltrate files from the system using a documents collector tool. |
| T1005 Data from Local System |
MalwareSTARWHALE | STARWHALE can collect data from an infected local host. |
| T1005 Data from Local System |
MalwarePcexter | Pcexter can upload files from targeted systems. |
| T1005 Data from Local System |
MalwareKevin | Kevin can upload logs and other data from a compromised host. |
| T1005 Data from Local System |
MalwarePasam | Pasam creates a backdoor through which remote attackers can retrieve files. |
| T1005 Data from Local System |
MalwarePOWERSTATS | POWERSTATS can upload files from compromised hosts. |
| T1005 Data from Local System |
MalwareBADNEWS | When it first starts, BADNEWS crawls the victim's local drives and collects documents with the following extensions: .doc, .docx, .pdf, .ppt, .pptx, and .txt. |
| T1005 Data from Local System |
MalwareLinfo | Linfo creates a backdoor through which remote attackers can obtain data from local systems. |
| T1005 Data from Local System |
MalwareGoopy | Goopy has the ability to exfiltrate documents from infected systems. |
| T1005 Data from Local System |
MalwareQakBot | QakBot can use a variety of commands, including esentutl.exe to steal sensitive data from Internet Explorer and Microsoft Edge, to acquire information that is subsequently exfiltrated. |
| T1005 Data from Local System |
MalwareCookieMiner | CookieMiner has retrieved iPhone text messages from iTunes phone backup files. |
| T1005 Data from Local System |
MalwareGelsemium | Gelsemium can collect data from a compromised host. |
| T1005 Data from Local System |
MalwareDtrack | Dtrack can collect a variety of information from victim machines. |
| T1005 Data from Local System |
MalwareZox | Zox has the ability to upload files from a targeted system. |
| T1005 Data from Local System |
MalwareUPPERCUT | UPPERCUT can upload files to the C2 from infected machines. |
| T1005 Data from Local System |
MalwareStrifeWater | StrifeWater can collect data from a compromised host. |
| T1005 Data from Local System |
MalwareWarzoneRAT | WarzoneRAT can collect data from a compromised host. |
| T1005 Data from Local System |
MalwareSLOTHFULMEDIA | SLOTHFULMEDIA has uploaded files and information from victim machines. |
| T1005 Data from Local System |
ToolNPPSPY | NPPSPY records data entered from the local system logon at Winlogon to capture credentials in cleartext. |
| T1005 Data from Local System |
ToolPowerSploit | PowerSploit contains a collection of Exfiltration modules that can access data from local files, volumes, and processes. |
| T1005 Data from Local System |
ToolPcShare | PcShare can collect files and information from a compromised host. |
| T1005 Data from Local System |
ToolBrute Ratel C4 | Brute Ratel C4 has the ability to upload files from a compromised system. |
| T1005 Data from Local System |
ToolTruffleHog | TruffleHog has gathered data from home directories of the victim environment. |
| T1005 Data from Local System |
ToolOut1 | Out1 can copy files and Registry data from compromised hosts. |
| T1005 Data from Local System |
ToolForfiles | Forfiles can be used to act on (ex: copy, move, etc.) files/directories in a system during (ex: copy files into a staging area before). |
| T1005 Data from Local System |
ToolMCMD | MCMD has the ability to upload files from an infected device. |
| T1005 Data from Local System |
Toolesentutl | esentutl can be used to collect data from local file systems. |
| T1005 Data from Local System |
ToolKoadic | Koadic can download files off the target system to send back to the server. |
| T1005 Data from Local System |
ToolQuasarRAT | QuasarRAT can retrieve files from compromised client machines. |
| T1005 Data from Local System |
ToolWevtutil | Wevtutil can be used to export events from a specific log. |
| T1005 Data from Local System |
GroupTeamPCP | TeamPCP has stolen source code from victim environments including Mistral AI. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.