ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1005×

169 examples

TechniqueUsed byProcedure example
T1005
Data from Local System
MalwareHiddenFace

HiddenFace can upload files from the victim machine to C2 nodes.

T1005
Data from Local System
MalwareCryptoistic

Cryptoistic can retrieve files from the local file system.

T1005
Data from Local System
MalwareMgBot

MgBot includes modules for collecting files from local systems based on a given set of properties and filenames.

T1005
Data from Local System
Malwareccf32

ccf32 can collect files from a compromised host.

T1005
Data from Local System
MalwareCobalt Strike

Cobalt Strike can collect data from a local system.

T1005
Data from Local System
MalwareSUNBURST

SUNBURST collected information from a compromised host.

T1005
Data from Local System
MalwareSamurai

Samurai can leverage an exfiltration module to download arbitrary files from compromised machines.

T1005
Data from Local System
MalwarePinchDuke

PinchDuke collects user files from the compromised host based on predefined file extensions.

T1005
Data from Local System
MalwareMilan

Milan can upload files from a compromised host.

T1005
Data from Local System
MalwareOSX_OCEANLOTUS.D

OSX_OCEANLOTUS.D has the ability to upload files from a compromised host.

T1005
Data from Local System
MalwareTaidoor

Taidoor can upload data and files from a victim's machine.

T1005
Data from Local System
MalwareCyclops Blink

Cyclops Blink can upload files from a compromised host.

T1005
Data from Local System
MalwarePoisonIvy

PoisonIvy creates a backdoor through which remote attackers can steal system information.

T1005
Data from Local System
MalwareTajMahal

TajMahal has the ability to steal documents from the local system including the print spooler queue.

T1005
Data from Local System
MalwareRaccoon Stealer

Raccoon Stealer collects data from victim machines based on configuration information received from command and control nodes.

T1005
Data from Local System
MalwareIPsec Helper

IPsec Helper can identify specific files and folders for follow-on exfiltration.

T1005
Data from Local System
MalwareDanBot

DanBot can upload files from compromised hosts.

T1005
Data from Local System
MalwareCalisto

Calisto can collect data from user directories.

T1005
Data from Local System
MalwareRamsay

Ramsay can collect Microsoft Word documents from the target's file system, as well as .txt, .doc, and .xls files from the Internet Explorer cache.

T1005
Data from Local System
MalwarePillowmint

Pillowmint has collected credit card data using native API functions.

T1005
Data from Local System
MalwareMacMa

MacMa can collect then exfiltrate files from the compromised system.

T1005
Data from Local System
MalwareFunnyDream

FunnyDream can upload files from victims' machines.

T1005
Data from Local System
MalwareSysUpdate

SysUpdate can collect information and files from a compromised host.

T1005
Data from Local System
MalwareOutSteel

OutSteel can collect information from a compromised host.

T1005
Data from Local System
MalwarePUNCHTRACK

PUNCHTRACK scrapes memory for properly formatted payment card data.

T1005
Data from Local System
MalwareLAMEHUG

LAMEHUG has the ability to collect system information and files of interest from compromised systems.

T1005
Data from Local System
MalwareGrimAgent

GrimAgent can collect data and files from a compromised host.

T1005
Data from Local System
MalwareStealBit

StealBit can upload data and files to the LockBit victim-shaming site.

T1005
Data from Local System
MalwareZxShell

ZxShell can transfer files from a compromised host.

T1005
Data from Local System
MalwareSLIGHTPULSE

SLIGHTPULSE can read files specified on the local system.

T1005
Data from Local System
MalwareSPAWNCHIMERA

SPAWNCHIMERA has extracted the device’s Linux kernel image (vmlinux).

T1005
Data from Local System
MalwareTroll Stealer

Troll Stealer gathers information from infected systems such as SSH information from the victim's `.ssh` directory. Troll Stealer collects information from local FileZilla installations and Microsoft Sticky Note.

T1005
Data from Local System
MalwarenjRAT

njRAT can collect data from a local system.

T1005
Data from Local System
MalwareIceApple

IceApple can collect files, passwords, and other data from a compromised host.

T1005
Data from Local System
MalwaremetaMain

metaMain can collect files and system information from a compromised host.

T1005
Data from Local System
MalwareSideTwist

SideTwist has the ability to upload files from a compromised host.

T1005
Data from Local System
MalwareMis-Type

Mis-Type has collected files and data from a compromised host.

T1005
Data from Local System
MalwareXCSSET

XCSSET collects contacts and application data from files in Desktop, Documents, Downloads, Dropbox, and WeChat folders.

T1005
Data from Local System
MalwareOctopus

Octopus can exfiltrate files from the system using a documents collector tool.

T1005
Data from Local System
MalwareSTARWHALE

STARWHALE can collect data from an infected local host.

T1005
Data from Local System
MalwarePcexter

Pcexter can upload files from targeted systems.

T1005
Data from Local System
MalwareKevin

Kevin can upload logs and other data from a compromised host.

T1005
Data from Local System
MalwarePasam

Pasam creates a backdoor through which remote attackers can retrieve files.

T1005
Data from Local System
MalwarePOWERSTATS

POWERSTATS can upload files from compromised hosts.

T1005
Data from Local System
MalwareBADNEWS

When it first starts, BADNEWS crawls the victim's local drives and collects documents with the following extensions: .doc, .docx, .pdf, .ppt, .pptx, and .txt.

T1005
Data from Local System
MalwareLinfo

Linfo creates a backdoor through which remote attackers can obtain data from local systems.

T1005
Data from Local System
MalwareGoopy

Goopy has the ability to exfiltrate documents from infected systems.

T1005
Data from Local System
MalwareQakBot

QakBot can use a variety of commands, including esentutl.exe to steal sensitive data from Internet Explorer and Microsoft Edge, to acquire information that is subsequently exfiltrated.

T1005
Data from Local System
MalwareCookieMiner

CookieMiner has retrieved iPhone text messages from iTunes phone backup files.

T1005
Data from Local System
MalwareGelsemium

Gelsemium can collect data from a compromised host.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.