ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

11362 examples

TechniqueUsed byProcedure example
T1005
Data from Local System
MalwarePillowmint

Pillowmint has collected credit card data using native API functions.

T1005
Data from Local System
MalwareMacMa

MacMa can collect then exfiltrate files from the compromised system.

T1005
Data from Local System
MalwareFunnyDream

FunnyDream can upload files from victims' machines.

T1005
Data from Local System
MalwareSysUpdate

SysUpdate can collect information and files from a compromised host.

T1005
Data from Local System
MalwareOutSteel

OutSteel can collect information from a compromised host.

T1005
Data from Local System
MalwarePUNCHTRACK

PUNCHTRACK scrapes memory for properly formatted payment card data.

T1005
Data from Local System
MalwareLAMEHUG

LAMEHUG has the ability to collect system information and files of interest from compromised systems.

T1005
Data from Local System
MalwareGrimAgent

GrimAgent can collect data and files from a compromised host.

T1005
Data from Local System
MalwareStealBit

StealBit can upload data and files to the LockBit victim-shaming site.

T1005
Data from Local System
MalwareZxShell

ZxShell can transfer files from a compromised host.

T1005
Data from Local System
MalwareSLIGHTPULSE

SLIGHTPULSE can read files specified on the local system.

T1005
Data from Local System
MalwareSPAWNCHIMERA

SPAWNCHIMERA has extracted the device’s Linux kernel image (vmlinux).

T1005
Data from Local System
MalwareTroll Stealer

Troll Stealer gathers information from infected systems such as SSH information from the victim's `.ssh` directory. Troll Stealer collects information from local FileZilla installations and Microsoft Sticky Note.

T1005
Data from Local System
MalwarenjRAT

njRAT can collect data from a local system.

T1005
Data from Local System
MalwareIceApple

IceApple can collect files, passwords, and other data from a compromised host.

T1005
Data from Local System
MalwaremetaMain

metaMain can collect files and system information from a compromised host.

T1005
Data from Local System
MalwareSideTwist

SideTwist has the ability to upload files from a compromised host.

T1005
Data from Local System
MalwareMis-Type

Mis-Type has collected files and data from a compromised host.

T1005
Data from Local System
MalwareXCSSET

XCSSET collects contacts and application data from files in Desktop, Documents, Downloads, Dropbox, and WeChat folders.

T1005
Data from Local System
MalwareOctopus

Octopus can exfiltrate files from the system using a documents collector tool.

T1005
Data from Local System
MalwareSTARWHALE

STARWHALE can collect data from an infected local host.

T1005
Data from Local System
MalwarePcexter

Pcexter can upload files from targeted systems.

T1005
Data from Local System
MalwareKevin

Kevin can upload logs and other data from a compromised host.

T1005
Data from Local System
MalwarePasam

Pasam creates a backdoor through which remote attackers can retrieve files.

T1005
Data from Local System
MalwarePOWERSTATS

POWERSTATS can upload files from compromised hosts.

T1005
Data from Local System
MalwareBADNEWS

When it first starts, BADNEWS crawls the victim's local drives and collects documents with the following extensions: .doc, .docx, .pdf, .ppt, .pptx, and .txt.

T1005
Data from Local System
MalwareLinfo

Linfo creates a backdoor through which remote attackers can obtain data from local systems.

T1005
Data from Local System
MalwareGoopy

Goopy has the ability to exfiltrate documents from infected systems.

T1005
Data from Local System
MalwareQakBot

QakBot can use a variety of commands, including esentutl.exe to steal sensitive data from Internet Explorer and Microsoft Edge, to acquire information that is subsequently exfiltrated.

T1005
Data from Local System
MalwareCookieMiner

CookieMiner has retrieved iPhone text messages from iTunes phone backup files.

T1005
Data from Local System
MalwareGelsemium

Gelsemium can collect data from a compromised host.

T1005
Data from Local System
MalwareDtrack

Dtrack can collect a variety of information from victim machines.

T1005
Data from Local System
MalwareZox

Zox has the ability to upload files from a targeted system.

T1005
Data from Local System
MalwareUPPERCUT

UPPERCUT can upload files to the C2 from infected machines.

T1005
Data from Local System
MalwareStrifeWater

StrifeWater can collect data from a compromised host.

T1005
Data from Local System
MalwareWarzoneRAT

WarzoneRAT can collect data from a compromised host.

T1005
Data from Local System
MalwareSLOTHFULMEDIA

SLOTHFULMEDIA has uploaded files and information from victim machines.

T1005
Data from Local System
ToolNPPSPY

NPPSPY records data entered from the local system logon at Winlogon to capture credentials in cleartext.

T1005
Data from Local System
ToolPowerSploit

PowerSploit contains a collection of Exfiltration modules that can access data from local files, volumes, and processes.

T1005
Data from Local System
ToolPcShare

PcShare can collect files and information from a compromised host.

T1005
Data from Local System
ToolBrute Ratel C4

Brute Ratel C4 has the ability to upload files from a compromised system.

T1005
Data from Local System
ToolTruffleHog

TruffleHog has gathered data from home directories of the victim environment.

T1005
Data from Local System
ToolOut1

Out1 can copy files and Registry data from compromised hosts.

T1005
Data from Local System
ToolForfiles

Forfiles can be used to act on (ex: copy, move, etc.) files/directories in a system during (ex: copy files into a staging area before).

T1005
Data from Local System
ToolMCMD

MCMD has the ability to upload files from an infected device.

T1005
Data from Local System
Toolesentutl

esentutl can be used to collect data from local file systems.

T1005
Data from Local System
ToolKoadic

Koadic can download files off the target system to send back to the server.

T1005
Data from Local System
ToolQuasarRAT

QuasarRAT can retrieve files from compromised client machines.

T1005
Data from Local System
ToolWevtutil

Wevtutil can be used to export events from a specific log.

T1005
Data from Local System
MalwareBADFLICK

BADFLICK has uploaded files from victims' machines.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.