ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1005
Data from Local System
GroupAndariel

Andariel has collected large numbers of files from compromised network systems for later extraction.

T1005
Data from Local System
GroupCURIUM

CURIUM has exfiltrated data from a compromised machine.

T1005
Data from Local System
GroupAPT39

APT39 has used various tools to steal files from the compromised host.

T1005
Data from Local System
GroupAPT37

APT37 has collected data from victims' local systems.

T1005
Data from Local System
GroupOilRig

OilRig has used PowerShell to upload files from compromised systems.

T1005
Data from Local System
GroupWindigo

Windigo has used a script to gather credentials in files left on disk by OpenSSH backdoors.

T1005
Data from Local System
GroupAquatic Panda

Aquatic Panda captured local Windows security event log data from victim machines using the wevtutil utility to extract contents to an evtx output file.

T1005
Data from Local System
GroupKe3chang

Ke3chang gathered information and files from local directories for exfiltration.

T1005
Data from Local System
GroupAPT1

APT1 has collected files from a local victim.

T1005
Data from Local System
GroupTurla

Turla RPC backdoors can upload files from victim machines.

T1005
Data from Local System
GroupRedCurl

RedCurl has collected data from the local disk of compromised hosts.

T1005
Data from Local System
GroupStealth Falcon

Stealth Falcon malware gathers data from the local victim system.

T1005
Data from Local System
GroupAPT29

APT29 has stolen data from compromised hosts.

T1005
Data from Local System
GroupDark Caracal

Dark Caracal collected complete contents of the 'Pictures' folder from compromised Windows systems.

T1005
Data from Local System
GroupMirrorFace

MirrorFace gathered data and files of interest from victim's systems.

T1005
Data from Local System
GroupBRONZE BUTLER

BRONZE BUTLER has exfiltrated files stolen from local systems.

T1005
Data from Local System
GroupAxiom

Axiom has collected data from a compromised network.

T1005
Data from Local System
GroupEmber Bear

Ember Bear gathers victim system information such as enumerating the volume of a given device or extracting system and security event logs for analysis.

T1005
Data from Local System
GroupToddyCat

ToddyCat has run scripts to collect documents from targeted hosts.

T1005
Data from Local System
GroupLuminousMoth

LuminousMoth has collected files and data from compromised machines.

T1005
Data from Local System
GroupAgrius

Agrius gathered data from database and other critical servers in victim environments, then used wiping mechanisms as an anti-analysis and anti-forensics mechanism.

T1005
Data from Local System
GroupAPT28

APT28 has retrieved internal documents from machines inside victim environments, including by using Forfiles to stage documents before exfiltration.

T1005
Data from Local System
GroupFox Kitten

Fox Kitten has searched local system resources to access sensitive documents.

T1005
Data from Local System
GroupLazarus Group

Lazarus Group has collected data and files from compromised networks.

T1005
Data from Local System
GroupLAPSUS$

LAPSUS$ uploaded sensitive files, information, and credentials from a targeted organization for extortion or public release.

T1005
Data from Local System
GroupWizard Spider

Wizard Spider has collected data from a compromised host prior to exfiltration.

T1005
Data from Local System
GroupInception

Inception used a file hunting plugin to collect .txt, .pdf, .xls or .doc files from the infected host.

T1005
Data from Local System
GroupVOID MANTICORE

VOID MANTICORE has collected cached data and files from within the victim environment.

T1005
Data from Local System
GroupMagic Hound

Magic Hound has used a web shell to exfiltrate a ZIP file containing a dump of LSASS memory on a compromised machine.

T1005
Data from Local System
GroupThreat Group-3390

Threat Group-3390 ran a command to compile an archive of file types of interest from the victim user's directories.

T1005
Data from Local System
GroupFIN13

FIN13 has gathered stolen credentials, sensitive data such as point-of-sale (POS), and ATM data from a compromised network before exfiltration.

T1005
Data from Local System
MalwareTrickBot

TrickBot collects local files and information from the victim’s local machine.

T1005
Data from Local System
MalwareBLINDINGCAN

BLINDINGCAN has uploaded files from victim machines.

T1005
Data from Local System
MalwareRCSession

RCSession can collect data from a compromised host.

T1005
Data from Local System
MalwareQuietSieve

QuietSieve can collect files from a compromised host.

T1005
Data from Local System
MalwareBumblebee

Bumblebee can capture and compress stolen credentials from the Registry and volume shadow copies.

T1005
Data from Local System
MalwareBRICKSTORM

BRICKSTORM has commands that allow the actor download files from the compromised host to the C2 server, and to also download specific sections of a file.

T1005
Data from Local System
MalwareAmadey

Amadey can collect information from a compromised host.

T1005
Data from Local System
MalwareProxysvc

Proxysvc searches the local system and gathers data.

T1005
Data from Local System
Malwareyty

yty collects files with the following extensions: .ppt, .pptx, .pdf, .doc, .docx, .xls, .xlsx, .docm, .rtf, .inp, .xlsm, .csv, .odt, .pps, .vcf and sends them back to the C2 server.

T1005
Data from Local System
MalwareKOPILUWAK

KOPILUWAK can gather information from compromised hosts.

T1005
Data from Local System
MalwareSardonic

Sardonic has the ability to collect data from a compromised machine to deliver to the attacker.

T1005
Data from Local System
MalwareMisdat

Misdat has collected files and data from a compromised host.

T1005
Data from Local System
MalwareUrsnif

Ursnif has collected files from victim machines, including certificates and cookies.

T1005
Data from Local System
MalwareCASTLETAP

CASTLETAP can execute a C2 command to transfer files from victim machines.

T1005
Data from Local System
MalwareThreatNeedle

ThreatNeedle can collect data and files from a compromised host.

T1005
Data from Local System
MalwareHavoc

Havoc can download files from the victim's computer.

T1005
Data from Local System
MalwareFrameworkPOS

FrameworkPOS can collect elements related to credit card data from process memory.

T1005
Data from Local System
MalwareGravityRAT

GravityRAT steals files with the following extensions: .docx, .doc, .pptx, .ppt, .xlsx, .xls, .rtf, and .pdf.

T1005
Data from Local System
MalwareInvisibleFerret

InvisibleFerret has collected data utilizing a script that contained a list of excluded files and directory names and naming patterns of interest such as environment and configuration files, documents, spreadsheets, and other files that contained the words secret, wallet, private, and password.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.