ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1005×

15 examples

TechniqueUsed byProcedure example
T1005
Data from Local System
CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group used malicious Trojans and DLL files to exfiltrate data from an infected host.

T1005
Data from Local System
CampaignSharePoint ToolShell Exploitation

During SharePoint ToolShell Exploitation, threat actors extracted information from the compromised systems.

T1005
Data from Local System
CampaignFrankenstein

During Frankenstein, the threat actors used Empire to gather various local system information.

T1005
Data from Local System
CampaignOperation Honeybee

During Operation Honeybee, the threat actors collected data from compromised hosts.

T1005
Data from Local System
CampaignOperation MidnightEclipse

During Operation MidnightEclipse, threat actors stole saved cookies and login data from targeted systems.

T1005
Data from Local System
CampaignCutting Edge

During Cutting Edge, threat actors stole the running configuration and cache data from targeted Ivanti Connect Secure VPNs.

T1005
Data from Local System
CampaignAnthropic AI-orchestrated Campaign

During the Anthropic AI-orchestrated Campaign, the adversary tasked Claude Code to automatically gather sensitive data stored within the local system to include credentials, system configurations and sensitive operational data.

T1005
Data from Local System
CampaignC0015

During C0015, the threat actors obtained files and data from the compromised network.

T1005
Data from Local System
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 extracted files from compromised networks.

T1005
Data from Local System
CampaignOperation CuckooBees

During Operation CuckooBees, the threat actors collected data, files, and other information from compromised networks.

T1005
Data from Local System
CampaignNight Dragon

During Night Dragon, the threat actors collected files and other data from compromised systems.

T1005
Data from Local System
CampaignOperation Wocao

During Operation Wocao, threat actors exfiltrated files and directories of interest from the targeted system.

T1005
Data from Local System
CampaignC0017

During C0017, APT41 collected information related to compromised machines as well as Personal Identifiable Information (PII) from victim networks.

T1005
Data from Local System
CampaignC0026

During C0026, the threat actors collected documents from compromised hosts.

T1005
Data from Local System
CampaignCostaRicto

During CostaRicto, the threat actors collected data and files from compromised networks.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.