Real-world descriptions of how a group, tool or campaign used a technique.
11362 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1005 Data from Local System |
MalwareBankshot | Bankshot collects files from the local system. |
| T1005 Data from Local System |
MalwareSharpDisco | SharpDisco has dropped a recent-files stealer plugin to `C:\Users\Public\WinSrcNT\It11.exe`. |
| T1005 Data from Local System |
MalwarexCaon | xCaon has uploaded files from victims' machines. |
| T1005 Data from Local System |
MalwareNebulae | Nebulae has the capability to upload collected files to C2. |
| T1005 Data from Local System |
MalwareRainyDay | RainyDay can use a file exfiltration tool to collect recently changed files on a compromised host. |
| T1005 Data from Local System |
MalwareAppleSeed | AppleSeed can collect data on a compromised host. |
| T1005 Data from Local System |
MalwareTinyTurla | TinyTurla can upload files from a compromised host. |
| T1005 Data from Local System |
MalwareCosmicDuke | CosmicDuke steals user files from local hard drives with file extensions that match a predefined list. |
| T1005 Data from Local System |
MalwareEnvyScout | EnvyScout can collect sensitive NTLM material from a compromised host. |
| T1005 Data from Local System |
MalwareCrimson | Crimson can collect information from a compromised host. |
| T1005 Data from Local System |
MalwareTomiris | Tomiris has the ability to collect recent files matching a hardcoded list of extensions prior to exfiltration. |
| T1005 Data from Local System |
MalwareDUSTTRAP | DUSTTRAP can gather data from infected systems. |
| T1005 Data from Local System |
MalwareMachete | Machete searches the File system for files of interest. |
| T1005 Data from Local System |
MalwarePowerLess | PowerLess has the ability to exfiltrate data, including Chrome and Edge browser database files, from compromised machines. |
| T1005 Data from Local System |
MalwareAction RAT | Action RAT can collect local data from an infected machine. |
| T1005 Data from Local System |
MalwarePingPull | PingPull can collect data from a compromised host. |
| T1005 Data from Local System |
MalwareWellMess | WellMess can send files from the victim machine to C2. |
| T1005 Data from Local System |
MalwareWoody RAT | Woody RAT can collect information from a compromised host. |
| T1005 Data from Local System |
MalwareMafalda | Mafalda can collect files and information from a compromised host. |
| T1005 Data from Local System |
MalwareAuTo Stealer | AuTo Stealer can collect data such as PowerPoint files, Word documents, Excel files, PDF files, text files, database files, and image files from an infected machine. |
| T1005 Data from Local System |
MalwareSombRAT | SombRAT has collected data and files from a compromised host. |
| T1005 Data from Local System |
MalwareFLASHFLOOD | FLASHFLOOD searches for interesting files (either a default or customized set of file extensions) on the local system. FLASHFLOOD will scan the My Recent Documents, Desktop, Temporary Internet Files, and TEMP directories. FLASHFLOOD also collects information stored in the Windows Address Book. |
| T1005 Data from Local System |
MalwareFlawedAmmyy | FlawedAmmyy has collected information and files from a compromised machine. |
| T1005 Data from Local System |
MalwareLoFiSe | LoFiSe can collect files of interest from targeted systems. |
| T1005 Data from Local System |
MalwareMobileOrder | MobileOrder exfiltrates data collected from the victim mobile device. |
| T1005 Data from Local System |
MalwareInvisiMole | InvisiMole can collect data from the system, and can monitor changes in specified directories. |
| T1005 Data from Local System |
MalwareP.A.S. Webshell | P.A.S. Webshell has the ability to copy files on a compromised host. |
| T1005 Data from Local System |
MalwareNeoichor | Neoichor can upload files from a victim's machine. |
| T1005 Data from Local System |
MalwareMarkiRAT | MarkiRAT can upload data from the victim's machine to the C2 server. |
| T1005 Data from Local System |
MalwareKazuar | Kazuar uploads files from a specified directory to the C2 server. |
| T1005 Data from Local System |
MalwareCHIMNEYSWEEP | CHIMNEYSWEEP can collect files from compromised hosts. |
| T1005 Data from Local System |
MalwareFatDuke | FatDuke can copy files and directories from a compromised host. |
| T1005 Data from Local System |
MalwareDRATzarus | DRATzarus can collect information from a compromised host. |
| T1005 Data from Local System |
MalwareRising Sun | Rising Sun has collected data and files from a compromised host. |
| T1005 Data from Local System |
MalwareShimRat | ShimRat has the capability to upload collected files to a C2. |
| T1005 Data from Local System |
MalwareChrommme | Chrommme can collect data from a local system. |
| T1005 Data from Local System |
MalwareFlagpro | Flagpro can collect data from a compromised host, including Windows authentication information. |
| T1005 Data from Local System |
MalwareSpicyOmelette | SpicyOmelette has collected data and other information from a compromised host. |
| T1005 Data from Local System |
MalwareGreen Lambert | Green Lambert can collect data from a compromised host. |
| T1005 Data from Local System |
MalwareChina Chopper | China Chopper's server component can upload local files. |
| T1005 Data from Local System |
MalwareBeaverTail | BeaverTail has exfiltrated data collected from local systems. |
| T1005 Data from Local System |
MalwareROKRAT | ROKRAT can collect host data and specific file types. |
| T1005 Data from Local System |
MalwareDarkWatchman | DarkWatchman can collect files from a compromised host. |
| T1005 Data from Local System |
MalwareBlackMould | BlackMould can copy files on a compromised host. |
| T1005 Data from Local System |
MalwareBisonal | Bisonal has collected information from a compromised host. |
| T1005 Data from Local System |
MalwareRover | Rover searches for files on local drives based on a predefined list of file extensions. |
| T1005 Data from Local System |
MalwareLightNeuron | LightNeuron can collect files from a local system. |
| T1005 Data from Local System |
MalwareClambling | Clambling can collect information from a compromised host. |
| T1005 Data from Local System |
MalwareDarkGate | DarkGate has stolen `sitemanager.xml` and `recentservers.xml` from `%APPDATA%\FileZilla\` if present. |
| T1005 Data from Local System |
MalwareMongall | Mongall has the ability to upload files from victim's machines. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.