Real-world descriptions of how a group, tool or campaign used a technique.
11362 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1005 Data from Local System |
MalwareSVCReady | SVCReady can collect data from an infected host. |
| T1005 Data from Local System |
MalwareFoggyWeb | FoggyWeb can retrieve configuration data from a compromised AD FS server. |
| T1005 Data from Local System |
MalwareHydraq | Hydraq creates a backdoor through which remote attackers can read data from files. |
| T1005 Data from Local System |
MalwareCreepyDrive | CreepyDrive can upload files to C2 from victim machines. |
| T1005 Data from Local System |
MalwareCaterpillar WebShell | Caterpillar WebShell has a module to collect information from the local database. |
| T1005 Data from Local System |
MalwareUSBferry | USBferry can collect information from an air-gapped host machine. |
| T1005 Data from Local System |
MalwareLatrodectus | Latrodectus can collect data from a compromised host using a stealer module. |
| T1005 Data from Local System |
MalwareSaint Bot | Saint Bot can collect files and information from a compromised host. |
| T1005 Data from Local System |
MalwareLODEINFO | LODEINFO can upload files from infected hosts to the C2. |
| T1005 Data from Local System |
MalwareCharmPower | CharmPower can collect data and files from a compromised host. |
| T1005 Data from Local System |
MalwareGlassWorm | GlassWorm has collected local data from a compromised host to include desktop cryptocurrency wallet data, and documents from within Desktop, Documents, and Downloads. |
| T1005 Data from Local System |
MalwareUroburos | Uroburos can use its `Get` command to exfiltrate specified files from the compromised system. |
| T1005 Data from Local System |
MalwareBandook | Bandook can collect local files from the system . |
| T1005 Data from Local System |
MalwareKONNI | KONNI has stored collected information and discovered processes in a tmp file. |
| T1005 Data from Local System |
MalwareRAPIDPULSE | RAPIDPULSE retrieves files from the victim system via encrypted commands sent to the web shell. |
| T1005 Data from Local System |
MalwareDnsSystem | DnsSystem can upload files from infected machines after receiving a command with `uploaddd` in the string. |
| T1005 Data from Local System |
MalwareKGH_SPY | KGH_SPY can send a file containing victim system information to C2. |
| T1005 Data from Local System |
MalwareIxeshe | Ixeshe can collect data from a local system. |
| T1005 Data from Local System |
MalwareRedLine Stealer | RedLine Stealer has collected data stored locally including chat logs and files associated with chat services such as Steam, Discord, and Telegram. |
| T1005 Data from Local System |
MalwareBoxCaon | BoxCaon can upload files from a compromised host. |
| T1005 Data from Local System |
MalwareNightClub | NightClub can use a file monitor to steal specific files from targeted systems. |
| T1005 Data from Local System |
MalwareCrutch | Crutch can exfiltrate files from compromised systems. |
| T1005 Data from Local System |
MalwareSDBbot | SDBbot has the ability to access the file system on a compromised host. |
| T1005 Data from Local System |
MalwareHikit | Hikit can upload files from compromised machines. |
| T1005 Data from Local System |
MalwareWellMail | WellMail can exfiltrate files from the victim machine. |
| T1005 Data from Local System |
MalwareRawPOS | RawPOS dumps memory from specific processes on a victim system, parses the dumped files, and scrapes them for credit card data. |
| T1005 Data from Local System |
MalwareZxxZ | ZxxZ can collect data from a compromised host. |
| T1005 Data from Local System |
MalwareDrovorub | Drovorub can transfer files from the victim machine. |
| T1005 Data from Local System |
MalwareShark | Shark can upload files to its C2. |
| T1005 Data from Local System |
MalwareBazar | Bazar can retrieve information from the infected machine. |
| T1005 Data from Local System |
MalwareBadPatch | BadPatch collects files from the local system that have the following extensions, then prepares them for exfiltration: .xls, .xlsx, .pdf, .mdb, .rar, .zip, .doc, .docx. |
| T1005 Data from Local System |
MalwareHiddenFace | HiddenFace can upload files from the victim machine to C2 nodes. |
| T1005 Data from Local System |
MalwareCryptoistic | Cryptoistic can retrieve files from the local file system. |
| T1005 Data from Local System |
MalwareMgBot | MgBot includes modules for collecting files from local systems based on a given set of properties and filenames. |
| T1005 Data from Local System |
Malwareccf32 | ccf32 can collect files from a compromised host. |
| T1005 Data from Local System |
MalwareCobalt Strike | Cobalt Strike can collect data from a local system. |
| T1005 Data from Local System |
MalwareSUNBURST | SUNBURST collected information from a compromised host. |
| T1005 Data from Local System |
MalwareSamurai | Samurai can leverage an exfiltration module to download arbitrary files from compromised machines. |
| T1005 Data from Local System |
MalwarePinchDuke | PinchDuke collects user files from the compromised host based on predefined file extensions. |
| T1005 Data from Local System |
MalwareMilan | Milan can upload files from a compromised host. |
| T1005 Data from Local System |
MalwareOSX_OCEANLOTUS.D | OSX_OCEANLOTUS.D has the ability to upload files from a compromised host. |
| T1005 Data from Local System |
MalwareTaidoor | Taidoor can upload data and files from a victim's machine. |
| T1005 Data from Local System |
MalwareCyclops Blink | Cyclops Blink can upload files from a compromised host. |
| T1005 Data from Local System |
MalwarePoisonIvy | PoisonIvy creates a backdoor through which remote attackers can steal system information. |
| T1005 Data from Local System |
MalwareTajMahal | TajMahal has the ability to steal documents from the local system including the print spooler queue. |
| T1005 Data from Local System |
MalwareRaccoon Stealer | Raccoon Stealer collects data from victim machines based on configuration information received from command and control nodes. |
| T1005 Data from Local System |
MalwareIPsec Helper | IPsec Helper can identify specific files and folders for follow-on exfiltration. |
| T1005 Data from Local System |
MalwareDanBot | DanBot can upload files from compromised hosts. |
| T1005 Data from Local System |
MalwareCalisto | Calisto can collect data from user directories. |
| T1005 Data from Local System |
MalwareRamsay | Ramsay can collect Microsoft Word documents from the target's file system, as well as |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.