Real-world descriptions of how a group, tool or campaign used a technique.
169 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1005 Data from Local System |
MalwareDtrack | Dtrack can collect a variety of information from victim machines. |
| T1005 Data from Local System |
MalwareZox | Zox has the ability to upload files from a targeted system. |
| T1005 Data from Local System |
MalwareUPPERCUT | UPPERCUT can upload files to the C2 from infected machines. |
| T1005 Data from Local System |
MalwareStrifeWater | StrifeWater can collect data from a compromised host. |
| T1005 Data from Local System |
MalwareWarzoneRAT | WarzoneRAT can collect data from a compromised host. |
| T1005 Data from Local System |
MalwareSLOTHFULMEDIA | SLOTHFULMEDIA has uploaded files and information from victim machines. |
| T1005 Data from Local System |
ToolNPPSPY | NPPSPY records data entered from the local system logon at Winlogon to capture credentials in cleartext. |
| T1005 Data from Local System |
ToolPowerSploit | PowerSploit contains a collection of Exfiltration modules that can access data from local files, volumes, and processes. |
| T1005 Data from Local System |
ToolPcShare | PcShare can collect files and information from a compromised host. |
| T1005 Data from Local System |
ToolBrute Ratel C4 | Brute Ratel C4 has the ability to upload files from a compromised system. |
| T1005 Data from Local System |
ToolTruffleHog | TruffleHog has gathered data from home directories of the victim environment. |
| T1005 Data from Local System |
ToolOut1 | Out1 can copy files and Registry data from compromised hosts. |
| T1005 Data from Local System |
ToolForfiles | Forfiles can be used to act on (ex: copy, move, etc.) files/directories in a system during (ex: copy files into a staging area before). |
| T1005 Data from Local System |
ToolMCMD | MCMD has the ability to upload files from an infected device. |
| T1005 Data from Local System |
Toolesentutl | esentutl can be used to collect data from local file systems. |
| T1005 Data from Local System |
ToolKoadic | Koadic can download files off the target system to send back to the server. |
| T1005 Data from Local System |
ToolQuasarRAT | QuasarRAT can retrieve files from compromised client machines. |
| T1005 Data from Local System |
ToolWevtutil | Wevtutil can be used to export events from a specific log. |
| T1005 Data from Local System |
MalwareBADFLICK | BADFLICK has uploaded files from victims' machines. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.