Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1074.001 Local Data Staging |
GroupBackdoorDiplomacy | BackdoorDiplomacy has copied files of interest to the main drive's recycle bin. |
| T1074.001 Local Data Staging |
GroupAgrius | Agrius has used the folder, |
| T1074.001 Local Data Staging |
GroupAPT28 | APT28 has stored captured credential information in a file named pi.log. |
| T1074.001 Local Data Staging |
GroupAPT5 | APT5 has staged data on compromised systems prior to exfiltration often in `C:\Users\Public`. |
| T1074.001 Local Data Staging |
GroupLazarus Group | Lazarus Group malware IndiaIndia saves information gathered about the victim to a file that is saved in the %TEMP% directory, then compressed, encrypted, and uploaded to a C2 server. |
| T1074.001 Local Data Staging |
GroupWizard Spider | Wizard Spider has staged ZIP files in local directories such as, `C:\PerfLogs\1\` and `C:\User\1\` prior to exfiltration. |
| T1074.001 Local Data Staging |
GroupWIRTE | WIRTE has staged collected documents of interest in `C:\Users\Public folder`. |
| T1074.001 Local Data Staging |
GroupThreat Group-3390 | Threat Group-3390 has locally staged encrypted archives for later exfiltration efforts. |
| T1074.001 Local Data Staging |
GroupFIN13 | FIN13 has utilized the following temporary folders on compromised Windows and Linux systems for their operations prior to exfiltration: `C:\Windows\Temp` and `/tmp`. |
| T1074.001 Local Data Staging |
MalwareExaramel for Windows | Exaramel for Windows specifies a path to store files scheduled for exfiltration. |
| T1074.001 Local Data Staging |
MalwareNOKKI | NOKKI can collect data from the victim and stage it in |
| T1074.001 Local Data Staging |
MalwareKOPILUWAK | KOPILUWAK has piped the results from executed C2 commands to `%TEMP%\result2.dat` on the local machine. |
| T1074.001 Local Data Staging |
MalwareVersaMem | VersaMem staged captured credentials locally at `/tmp/.temp.data`. |
| T1074.001 Local Data Staging |
MalwarePAKLOG | PAKLOG has stored the captured data in a file located `C:\\Users\\Public\\Libraries\\record.txt`. |
| T1074.001 Local Data Staging |
MalwareUrsnif | Ursnif has used tmp files to stage gathered information. |
| T1074.001 Local Data Staging |
MalwareFrameworkPOS | FrameworkPOS can identifiy payment card track data on the victim and copy it to a local file in a subdirectory of C:\Windows\. |
| T1074.001 Local Data Staging |
MalwareInvisibleFerret | InvisibleFerret has staged data in consolidated folders prior to exfiltration. |
| T1074.001 Local Data Staging |
MalwareRainyDay | RainyDay can use a file exfiltration tool to copy files to |
| T1074.001 Local Data Staging |
MalwareAppleSeed | AppleSeed can stage files in a central location prior to exfiltration. |
| T1074.001 Local Data Staging |
MalwareNETWIRE | NETWIRE has the ability to write collected data to a file created in the |
| T1074.001 Local Data Staging |
MalwareMirrorStealer | MirrorStealer has stored stolen credentials on the local machine in `%TEMP%\31558.txt`. |
| T1074.001 Local Data Staging |
MalwareTurian | Turian can store copied files in a specific directory prior to exfiltration. |
| T1074.001 Local Data Staging |
MalwareMachete | Machete stores files and logs in a folder on the local drive. |
| T1074.001 Local Data Staging |
MalwarePowerLess | PowerLess can stage stolen browser data in `C:\\Windows\\Temp\\cup.tmp` and keylogger data in `C:\\Windows\\Temp\\Report.06E17A5A-7325-4325-8E5D-E172EBA7FC5BK`. |
| T1074.001 Local Data Staging |
MalwarePrikormka | Prikormka creates a directory, |
| T1074.001 Local Data Staging |
MalwareMafalda | Mafalda can place retrieved files into a destination directory. |
| T1074.001 Local Data Staging |
MalwareAuTo Stealer | AuTo Stealer can store collected data from an infected host to a file named `Hostname_UserName.txt` prior to exfiltration. |
| T1074.001 Local Data Staging |
MalwareSombRAT | SombRAT can store harvested data in a custom database under the %TEMP% directory. |
| T1074.001 Local Data Staging |
MalwareFLASHFLOOD | FLASHFLOOD stages data it copies from the local system or removable drives in the "%WINDIR%\$NtUninstallKB885884$\" directory. |
| T1074.001 Local Data Staging |
MalwareLoFiSe | LoFiSe can save files to be evaluated for further exfiltration in the `C:\Programdata\Microsoft\` and `C:\windows\temp\` folders. |
| T1074.001 Local Data Staging |
MalwareCuckoo Stealer | Cuckoo Stealer has staged collected application data from Safari, Notes, and Keychain to `/var/folder`. |
| T1074.001 Local Data Staging |
MalwareInvisiMole | InvisiMole determines a working directory where it stores all the gathered data about the compromised machine. |
| T1074.001 Local Data Staging |
MalwareMarkiRAT | MarkiRAT can store collected data locally in a created .nfo file. |
| T1074.001 Local Data Staging |
MalwareKazuar | Kazuar stages command output and collected data in files before exfiltration. |
| T1074.001 Local Data Staging |
MalwareNavRAT | NavRAT writes multiple outputs to a TMP file using the >> method. |
| T1074.001 Local Data Staging |
MalwareCHIMNEYSWEEP | CHIMNEYSWEEP can store captured screenshots to disk including to a covert store named `APPX.%x%x%x%x%x.tmp` where `%x` is a random value. |
| T1074.001 Local Data Staging |
MalwareChrommme | Chrommme can store captured system information locally prior to exfiltration. |
| T1074.001 Local Data Staging |
MalwareObliqueRAT | ObliqueRAT can copy specific files, webcam captures, and screenshots to local directories. |
| T1074.001 Local Data Staging |
MalwareSocGholish | SocGholish can send output from `whoami` to a local temp file using the naming convention `rad<5-hex-chars>.tmp`. |
| T1074.001 Local Data Staging |
MalwarePUNCHBUGGY | PUNCHBUGGY has saved information to a random temp file before exfil. |
| T1074.001 Local Data Staging |
MalwarePteranodon | Pteranodon creates various subdirectories under |
| T1074.001 Local Data Staging |
MalwareBeaverTail | BeaverTail has staged collected data to the system’s temporary directory. |
| T1074.001 Local Data Staging |
MalwareDarkWatchman | DarkWatchman can stage local data in the Windows Registry. |
| T1074.001 Local Data Staging |
MalwareDyre | Dyre has the ability to create files in a TEMP folder to act as a database to store information. |
| T1074.001 Local Data Staging |
MalwarePACEMAKER | PACEMAKER has written extracted data to `tmp/dsserver-check.statementcounters`. |
| T1074.001 Local Data Staging |
MalwarePlugX | PlugX has collected and staged the victim’s computer files for exfiltration. |
| T1074.001 Local Data Staging |
MalwareLumma Stealer | Lumma Stealer has configured a custom user data directory such as a folder within `%USERPROFILE%\AppData\Roaming` for staging data. |
| T1074.001 Local Data Staging |
MalwareDustySky | DustySky created folders in temp directories to host collected files before exfiltration. |
| T1074.001 Local Data Staging |
MalwareRover | Rover copies files from removable drives to |
| T1074.001 Local Data Staging |
MalwareLightNeuron | LightNeuron can store email data in files and directories specified in its configuration, such as |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.