ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1005
Data from Local System
MalwareSVCReady

SVCReady can collect data from an infected host.

T1005
Data from Local System
MalwareFoggyWeb

FoggyWeb can retrieve configuration data from a compromised AD FS server.

T1005
Data from Local System
MalwareHydraq

Hydraq creates a backdoor through which remote attackers can read data from files.

T1005
Data from Local System
MalwareCreepyDrive

CreepyDrive can upload files to C2 from victim machines.

T1005
Data from Local System
MalwareCaterpillar WebShell

Caterpillar WebShell has a module to collect information from the local database.

T1005
Data from Local System
MalwareUSBferry

USBferry can collect information from an air-gapped host machine.

T1005
Data from Local System
MalwareLatrodectus

Latrodectus can collect data from a compromised host using a stealer module.

T1005
Data from Local System
MalwareSaint Bot

Saint Bot can collect files and information from a compromised host.

T1005
Data from Local System
MalwareLODEINFO

LODEINFO can upload files from infected hosts to the C2.

T1005
Data from Local System
MalwareCharmPower

CharmPower can collect data and files from a compromised host.

T1005
Data from Local System
MalwareGlassWorm

GlassWorm has collected local data from a compromised host to include desktop cryptocurrency wallet data, and documents from within Desktop, Documents, and Downloads.

T1005
Data from Local System
MalwareUroburos

Uroburos can use its `Get` command to exfiltrate specified files from the compromised system.

T1005
Data from Local System
MalwareBandook

Bandook can collect local files from the system .

T1005
Data from Local System
MalwareKONNI

KONNI has stored collected information and discovered processes in a tmp file.

T1005
Data from Local System
MalwareRAPIDPULSE

RAPIDPULSE retrieves files from the victim system via encrypted commands sent to the web shell.

T1005
Data from Local System
MalwareDnsSystem

DnsSystem can upload files from infected machines after receiving a command with `uploaddd` in the string.

T1005
Data from Local System
MalwareKGH_SPY

KGH_SPY can send a file containing victim system information to C2.

T1005
Data from Local System
MalwareIxeshe

Ixeshe can collect data from a local system.

T1005
Data from Local System
MalwareRedLine Stealer

RedLine Stealer has collected data stored locally including chat logs and files associated with chat services such as Steam, Discord, and Telegram.

T1005
Data from Local System
MalwareBoxCaon

BoxCaon can upload files from a compromised host.

T1005
Data from Local System
MalwareNightClub

NightClub can use a file monitor to steal specific files from targeted systems.

T1005
Data from Local System
MalwareCrutch

Crutch can exfiltrate files from compromised systems.

T1005
Data from Local System
MalwareSDBbot

SDBbot has the ability to access the file system on a compromised host.

T1005
Data from Local System
MalwareHikit

Hikit can upload files from compromised machines.

T1005
Data from Local System
MalwareWellMail

WellMail can exfiltrate files from the victim machine.

T1005
Data from Local System
MalwareRawPOS

RawPOS dumps memory from specific processes on a victim system, parses the dumped files, and scrapes them for credit card data.

T1005
Data from Local System
MalwareZxxZ

ZxxZ can collect data from a compromised host.

T1005
Data from Local System
MalwareDrovorub

Drovorub can transfer files from the victim machine.

T1005
Data from Local System
MalwareShark

Shark can upload files to its C2.

T1005
Data from Local System
MalwareBazar

Bazar can retrieve information from the infected machine.

T1005
Data from Local System
MalwareBadPatch

BadPatch collects files from the local system that have the following extensions, then prepares them for exfiltration: .xls, .xlsx, .pdf, .mdb, .rar, .zip, .doc, .docx.

T1005
Data from Local System
MalwareHiddenFace

HiddenFace can upload files from the victim machine to C2 nodes.

T1005
Data from Local System
MalwareCryptoistic

Cryptoistic can retrieve files from the local file system.

T1005
Data from Local System
MalwareMgBot

MgBot includes modules for collecting files from local systems based on a given set of properties and filenames.

T1005
Data from Local System
Malwareccf32

ccf32 can collect files from a compromised host.

T1005
Data from Local System
MalwareCobalt Strike

Cobalt Strike can collect data from a local system.

T1005
Data from Local System
MalwareSUNBURST

SUNBURST collected information from a compromised host.

T1005
Data from Local System
MalwareSamurai

Samurai can leverage an exfiltration module to download arbitrary files from compromised machines.

T1005
Data from Local System
MalwarePinchDuke

PinchDuke collects user files from the compromised host based on predefined file extensions.

T1005
Data from Local System
MalwareMilan

Milan can upload files from a compromised host.

T1005
Data from Local System
MalwareOSX_OCEANLOTUS.D

OSX_OCEANLOTUS.D has the ability to upload files from a compromised host.

T1005
Data from Local System
MalwareTaidoor

Taidoor can upload data and files from a victim's machine.

T1005
Data from Local System
MalwareCyclops Blink

Cyclops Blink can upload files from a compromised host.

T1005
Data from Local System
MalwarePoisonIvy

PoisonIvy creates a backdoor through which remote attackers can steal system information.

T1005
Data from Local System
MalwareTajMahal

TajMahal has the ability to steal documents from the local system including the print spooler queue.

T1005
Data from Local System
MalwareRaccoon Stealer

Raccoon Stealer collects data from victim machines based on configuration information received from command and control nodes.

T1005
Data from Local System
MalwareIPsec Helper

IPsec Helper can identify specific files and folders for follow-on exfiltration.

T1005
Data from Local System
MalwareDanBot

DanBot can upload files from compromised hosts.

T1005
Data from Local System
MalwareCalisto

Calisto can collect data from user directories.

T1005
Data from Local System
MalwareRamsay

Ramsay can collect Microsoft Word documents from the target's file system, as well as .txt, .doc, and .xls files from the Internet Explorer cache.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.