Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1005 Data from Local System |
GroupAndariel | Andariel has collected large numbers of files from compromised network systems for later extraction. |
| T1005 Data from Local System |
GroupCURIUM | CURIUM has exfiltrated data from a compromised machine. |
| T1005 Data from Local System |
GroupAPT39 | APT39 has used various tools to steal files from the compromised host. |
| T1005 Data from Local System |
GroupAPT37 | APT37 has collected data from victims' local systems. |
| T1005 Data from Local System |
GroupOilRig | OilRig has used PowerShell to upload files from compromised systems. |
| T1005 Data from Local System |
GroupWindigo | Windigo has used a script to gather credentials in files left on disk by OpenSSH backdoors. |
| T1005 Data from Local System |
GroupAquatic Panda | Aquatic Panda captured local Windows security event log data from victim machines using the |
| T1005 Data from Local System |
GroupKe3chang | Ke3chang gathered information and files from local directories for exfiltration. |
| T1005 Data from Local System |
GroupAPT1 | APT1 has collected files from a local victim. |
| T1005 Data from Local System |
GroupTurla | Turla RPC backdoors can upload files from victim machines. |
| T1005 Data from Local System |
GroupRedCurl | RedCurl has collected data from the local disk of compromised hosts. |
| T1005 Data from Local System |
GroupStealth Falcon | Stealth Falcon malware gathers data from the local victim system. |
| T1005 Data from Local System |
GroupAPT29 | APT29 has stolen data from compromised hosts. |
| T1005 Data from Local System |
GroupDark Caracal | Dark Caracal collected complete contents of the 'Pictures' folder from compromised Windows systems. |
| T1005 Data from Local System |
GroupMirrorFace | MirrorFace gathered data and files of interest from victim's systems. |
| T1005 Data from Local System |
GroupBRONZE BUTLER | BRONZE BUTLER has exfiltrated files stolen from local systems. |
| T1005 Data from Local System |
GroupAxiom | Axiom has collected data from a compromised network. |
| T1005 Data from Local System |
GroupEmber Bear | Ember Bear gathers victim system information such as enumerating the volume of a given device or extracting system and security event logs for analysis. |
| T1005 Data from Local System |
GroupToddyCat | ToddyCat has run scripts to collect documents from targeted hosts. |
| T1005 Data from Local System |
GroupLuminousMoth | LuminousMoth has collected files and data from compromised machines. |
| T1005 Data from Local System |
GroupAgrius | Agrius gathered data from database and other critical servers in victim environments, then used wiping mechanisms as an anti-analysis and anti-forensics mechanism. |
| T1005 Data from Local System |
GroupAPT28 | APT28 has retrieved internal documents from machines inside victim environments, including by using Forfiles to stage documents before exfiltration. |
| T1005 Data from Local System |
GroupFox Kitten | Fox Kitten has searched local system resources to access sensitive documents. |
| T1005 Data from Local System |
GroupLazarus Group | Lazarus Group has collected data and files from compromised networks. |
| T1005 Data from Local System |
GroupLAPSUS$ | LAPSUS$ uploaded sensitive files, information, and credentials from a targeted organization for extortion or public release. |
| T1005 Data from Local System |
GroupWizard Spider | Wizard Spider has collected data from a compromised host prior to exfiltration. |
| T1005 Data from Local System |
GroupInception | Inception used a file hunting plugin to collect .txt, .pdf, .xls or .doc files from the infected host. |
| T1005 Data from Local System |
GroupVOID MANTICORE | VOID MANTICORE has collected cached data and files from within the victim environment. |
| T1005 Data from Local System |
GroupMagic Hound | Magic Hound has used a web shell to exfiltrate a ZIP file containing a dump of LSASS memory on a compromised machine. |
| T1005 Data from Local System |
GroupThreat Group-3390 | Threat Group-3390 ran a command to compile an archive of file types of interest from the victim user's directories. |
| T1005 Data from Local System |
GroupFIN13 | FIN13 has gathered stolen credentials, sensitive data such as point-of-sale (POS), and ATM data from a compromised network before exfiltration. |
| T1005 Data from Local System |
MalwareTrickBot | TrickBot collects local files and information from the victim’s local machine. |
| T1005 Data from Local System |
MalwareBLINDINGCAN | BLINDINGCAN has uploaded files from victim machines. |
| T1005 Data from Local System |
MalwareRCSession | RCSession can collect data from a compromised host. |
| T1005 Data from Local System |
MalwareQuietSieve | QuietSieve can collect files from a compromised host. |
| T1005 Data from Local System |
MalwareBumblebee | Bumblebee can capture and compress stolen credentials from the Registry and volume shadow copies. |
| T1005 Data from Local System |
MalwareBRICKSTORM | BRICKSTORM has commands that allow the actor download files from the compromised host to the C2 server, and to also download specific sections of a file. |
| T1005 Data from Local System |
MalwareAmadey | Amadey can collect information from a compromised host. |
| T1005 Data from Local System |
MalwareProxysvc | Proxysvc searches the local system and gathers data. |
| T1005 Data from Local System |
Malwareyty | yty collects files with the following extensions: .ppt, .pptx, .pdf, .doc, .docx, .xls, .xlsx, .docm, .rtf, .inp, .xlsm, .csv, .odt, .pps, .vcf and sends them back to the C2 server. |
| T1005 Data from Local System |
MalwareKOPILUWAK | KOPILUWAK can gather information from compromised hosts. |
| T1005 Data from Local System |
MalwareSardonic | Sardonic has the ability to collect data from a compromised machine to deliver to the attacker. |
| T1005 Data from Local System |
MalwareMisdat | Misdat has collected files and data from a compromised host. |
| T1005 Data from Local System |
MalwareUrsnif | Ursnif has collected files from victim machines, including certificates and cookies. |
| T1005 Data from Local System |
MalwareCASTLETAP | CASTLETAP can execute a C2 command to transfer files from victim machines. |
| T1005 Data from Local System |
MalwareThreatNeedle | ThreatNeedle can collect data and files from a compromised host. |
| T1005 Data from Local System |
MalwareHavoc | Havoc can download files from the victim's computer. |
| T1005 Data from Local System |
MalwareFrameworkPOS | FrameworkPOS can collect elements related to credit card data from process memory. |
| T1005 Data from Local System |
MalwareGravityRAT | GravityRAT steals files with the following extensions: .docx, .doc, .pptx, .ppt, .xlsx, .xls, .rtf, and .pdf. |
| T1005 Data from Local System |
MalwareInvisibleFerret | InvisibleFerret has collected data utilizing a script that contained a list of excluded files and directory names and naming patterns of interest such as environment and configuration files, documents, spreadsheets, and other files that contained the words secret, wallet, private, and password. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.