T1005 Data from Local System — ATT&CK Technique
Adversaries may search local system sources, such as file systems, configuration files, local databases, virtual machine files, or process memory, to find files of interest and sensitive data prior to Exfiltration. Adversaries may do this using a Command and Scripting Interpreter, such as cmd as well as a Network Device CLI, which have functionality to interact with the file system to gather information. Adversaries may also use Automated Collection on the local system.
Detection coverage (21)
- Potential Conti Ransomware Database Dumping Activity Via SQLCmd high
- Shai-Hulud NPM Package Malicious Exfiltration via Curl high
- OpenCanary - SMB File Open Request high
- AWS EC2 VM Export Failure low
- Cisco Collect Data low
- Script Interpreter Spawning Credential Scanner - Linux high
- Crash Dump Created By Operating System medium
- ADFS Database Named Pipe Connection By Uncommon Tool medium
- Esentutl Steals Browser Information medium
- Veeam Backup Database Suspicious Query medium
- SQLite Chromium Profile Data DB Access high
- VeeamBackup Database Credentials Dump Via Sqlcmd.EXE high
- SQLite Firefox Profile Data DB Access high
- Script Interpreter Spawning Credential Scanner - Windows high
- Cisco ASA - Device File Copy Activity
- Cisco ASA - Device File Copy to Remote Location
- ESXi Sensitive Files Accessed
- ESXi VM Exported via Remote Tool
- PTC Windchill Gateway Command Execution
- Sqlite Module In Temp Folder
- Cisco TFTP Server Configuration for Data Exfiltration
Malware using this technique
- TrickBot
- BLINDINGCAN
- RCSession
- QuietSieve
- Bumblebee
- BRICKSTORM
- Amadey
- Proxysvc
- yty
- Bandook
- KONNI
- KOPILUWAK
- Sardonic
- Misdat
- Ursnif
- ThreatNeedle
- ShimRat
- Chrommme
- Havoc
- FrameworkPOS
- GravityRAT
- Bankshot
- SharpDisco
- xCaon
- Nebulae
- RainyDay
- AppleSeed
- TinyTurla
- CosmicDuke
- EnvyScout
- Crimson
- Tomiris
- DUSTTRAP
- Machete
- PowerLess
- Clambling
- PingPull
- WellMess
- Woody RAT
- Mafalda
- AuTo Stealer
- SombRAT
- FLASHFLOOD
- FlawedAmmyy
- LoFiSe
- DarkWatchman
- MobileOrder
- InvisiMole
- P.A.S. Webshell
- Neoichor
Threat actors using this technique
- Volt Typhoon
- APT3
- Inception
- Void Manticore
- GALLIUM
- Kimsuky
- Patchwork
- APT41
- Dragonfly
- APT10
- HAFNIUM
- FIN6
- Gamaredon Group
- FIN7
- Sandworm Team
- Andariel
- CURIUM
- APT39
- APT37
- OilRig
- Windigo
- APT35
- Aquatic Panda
- APT15
- APT1
- Turla
- APT27
- RedCurl
- Stealth Falcon
- APT29
- Dark Caracal
- MirrorFace
- BRONZE BUTLER
- Ember Bear
- Axiom
- ToddyCat
- LuminousMoth
- Agrius
- APT28
- Fox Kitten
- Lazarus Group
- LAPSUS$
- Conti
- APT38
- FIN13
- TeamPCP