ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1005×

169 examples

TechniqueUsed byProcedure example
T1005
Data from Local System
MalwareDtrack

Dtrack can collect a variety of information from victim machines.

T1005
Data from Local System
MalwareZox

Zox has the ability to upload files from a targeted system.

T1005
Data from Local System
MalwareUPPERCUT

UPPERCUT can upload files to the C2 from infected machines.

T1005
Data from Local System
MalwareStrifeWater

StrifeWater can collect data from a compromised host.

T1005
Data from Local System
MalwareWarzoneRAT

WarzoneRAT can collect data from a compromised host.

T1005
Data from Local System
MalwareSLOTHFULMEDIA

SLOTHFULMEDIA has uploaded files and information from victim machines.

T1005
Data from Local System
ToolNPPSPY

NPPSPY records data entered from the local system logon at Winlogon to capture credentials in cleartext.

T1005
Data from Local System
ToolPowerSploit

PowerSploit contains a collection of Exfiltration modules that can access data from local files, volumes, and processes.

T1005
Data from Local System
ToolPcShare

PcShare can collect files and information from a compromised host.

T1005
Data from Local System
ToolBrute Ratel C4

Brute Ratel C4 has the ability to upload files from a compromised system.

T1005
Data from Local System
ToolTruffleHog

TruffleHog has gathered data from home directories of the victim environment.

T1005
Data from Local System
ToolOut1

Out1 can copy files and Registry data from compromised hosts.

T1005
Data from Local System
ToolForfiles

Forfiles can be used to act on (ex: copy, move, etc.) files/directories in a system during (ex: copy files into a staging area before).

T1005
Data from Local System
ToolMCMD

MCMD has the ability to upload files from an infected device.

T1005
Data from Local System
Toolesentutl

esentutl can be used to collect data from local file systems.

T1005
Data from Local System
ToolKoadic

Koadic can download files off the target system to send back to the server.

T1005
Data from Local System
ToolQuasarRAT

QuasarRAT can retrieve files from compromised client machines.

T1005
Data from Local System
ToolWevtutil

Wevtutil can be used to export events from a specific log.

T1005
Data from Local System
MalwareBADFLICK

BADFLICK has uploaded files from victims' machines.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.