T1005 Data from Local System — ATT&CK Technique
Adversaries may search local system sources, such as file systems, configuration files, local databases, virtual machine files, or process memory, to find files of interest and sensitive data prior to Exfiltration. Adversaries may do this using a Command and Scripting Interpreter, such as cmd as well as a Network Device CLI, which have functionality to interact with the file system to gather information. Adversaries may also use Automated Collection on the local system.
Detection coverage (21)
- Potential Conti Ransomware Database Dumping Activity Via SQLCmd high
- Shai-Hulud NPM Package Malicious Exfiltration via Curl high
- OpenCanary - SMB File Open Request high
- AWS EC2 VM Export Failure low
- Cisco Collect Data low
- Script Interpreter Spawning Credential Scanner - Linux high
- Crash Dump Created By Operating System medium
- ADFS Database Named Pipe Connection By Uncommon Tool medium
- Esentutl Steals Browser Information medium
- Veeam Backup Database Suspicious Query medium
- SQLite Chromium Profile Data DB Access high
- VeeamBackup Database Credentials Dump Via Sqlcmd.EXE high
- SQLite Firefox Profile Data DB Access high
- Script Interpreter Spawning Credential Scanner - Windows high
- Cisco ASA - Device File Copy Activity
- Cisco ASA - Device File Copy to Remote Location
- ESXi Sensitive Files Accessed
- ESXi VM Exported via Remote Tool
- PTC Windchill Gateway Command Execution
- Sqlite Module In Temp Folder
- Cisco TFTP Server Configuration for Data Exfiltration
Malware using this technique
- Troll Stealer
- Proxysvc
- Drovorub
- Cryptoistic
- xCaon
- Shark
- Woody RAT
- XCSSET
- QakBot
- ccf32
- Dtrack
- Bankshot
- BADNEWS
- SVCReady
- Rising Sun
- PUNCHTRACK
- China Chopper
- Uroburos
- Octopus
- FLASHFLOOD
- P.A.S. Webshell
- Cobalt Strike
- GrimAgent
- NightClub
- Nebulae
- KONNI
- RedLine Stealer
- WarzoneRAT
- PingPull
- PowerSploit
- RAPIDPULSE
- Caterpillar WebShell
- Amadey
- BLINDINGCAN
- SombRAT
- Ramsay
- Raccoon Stealer
- MarkiRAT
- SPAWNCHIMERA
- OutSteel
- WellMess
- Latrodectus
- Mafalda
- SysUpdate
- yty
- Bumblebee
- EnvyScout
- LODEINFO
- USBferry
- Hydraq
Threat actors using this technique
- Volt Typhoon
- APT10
- Kimsuky
- BRONZE BUTLER
- LAPSUS$
- APT39
- HAFNIUM
- Axiom
- OilRig
- ToddyCat
- Windigo
- Fox Kitten
- Andariel
- RedCurl
- APT1
- GALLIUM
- Conti
- APT29
- Lazarus Group
- Gamaredon Group
- Agrius
- FIN6
- Aquatic Panda
- Turla
- APT41
- APT37
- Dragonfly
- CURIUM
- APT28
- Inception
- APT15
- Patchwork
- APT3
- MirrorFace
- APT27
- FIN7
- Void Manticore
- APT35
- Dark Caracal
- Ember Bear
- Stealth Falcon
- APT38
- Sandworm Team
- FIN13