FORENSIA

ATT&CK · T1005

Data from Local System

Tactics: collection

About

Adversaries may search local system sources, such as file systems, configuration files, local databases, virtual machine files, or process memory, to find files of interest and sensitive data prior to Exfiltration. Adversaries may do this using a Command and Scripting Interpreter, such as cmd as well as a Network Device CLI, which have functionality to interact with the file system to gather information. Adversaries may also use Automated Collection on the local system.

Platforms: ESXi, Linux, macOS, Network Devices, WindowsMITRE ATT&CK ↗

Used by actors

45 known groups

Software

169 malware/tools implement this

HikitTaidoorPoisonIvyIxesheChina ChopperUroburosFLASHFLOODPinchDukeCosmicDukeMobileOrderMisdatMis-TypeRoverCrimsonBADNEWSCobalt StrikeRawPOSForfilesPowerSploitPUNCHTRACKHydraqPasamLinfoPOWERSTATSBandookGravityRATProxysvcBankshotROKRATytyKoadicInvisiMoleQuasarRATKazuarTrickBotBisonalCalistoUPPERCUTBadPatchOctopusOSX_OCEANLOTUS.DKONNIFlawedAmmyynjRATUrsnifLightNeuronesentutlMacheteZxShellShimRatRising SunUSBferryRamsaySDBbotTajMahalGoopyCookieMinerCryptoisticMCMDDrovorubFrameworkPOSFatDukeWellMessWellMailPillowmintBLINDINGCANKGH_SPYSLOTHFULMEDIABazarCrutchSUNBURSTBlackMouldDtrackCaterpillar WebShellOut1P.A.S. WebshellSideTwistSombRATAppleSeedRainyDayNebulaeGrimAgentEnvyScoutBADFLICKWevtutilSpicyOmeletteQakBotBoxCaonMarkiRATxCaonXCSSETClamblingFoggyWebRCSessionSysUpdateThreatNeedleGelsemiumChrommmeTinyTurlaWarzoneRATTomirisZoxDarkWatchmanCharmPowerQuietSieveCyclops BlinkGreen LambertNeoichorDRATzarusFlagproPowerLessZxxZDanBotMilanMacMaOutSteelSaint BotSharkKevinDnsSystemIceAppleCreepyDriveAmadeyMongallAction RATAuTo StealerPingPullStrifeWaterSTARWHALEBumblebeeccf32FunnyDreamPcSharemetaMainMafaldaBrute Ratel C4SVCReadyWoody RATKOPILUWAKSardonicSharpDiscoNightClubSamuraiLoFiSePcexterSLIGHTPULSEDarkGateRAPIDPULSENPPSPYIPsec HelperMgBotRaccoon StealerCHIMNEYSWEEPDUSTTRAPLatrodectusTroll StealerStealBitCASTLETAPHavocRedLine StealerInvisibleFerretBeaverTailTruffleHogGlassWormBRICKSTORMLODEINFOHiddenFaceSPAWNCHIMERALAMEHUG

Corpus indicators tagged with this technique

5,738 indicators in the corpus carry T1005.

IndicatorTypeFamilySevSrc
cve-2025-12057cve851
cve-2020-22653cve852
cve-2026-0740cve851
cve-2025-7443cve851
cve-2025-2492cve852
cve-2025-68670cve852
cve-2020-22658cve852
cve-2026-1969cve851
cve-2025-34085cve851
cve-2025-7852cve851
cve-2026-3844cve851
cve-2021-29441cve851
f0038a5f46720da5982b6984ceef10cf99359432e102b12a0b0657498d36f670sha256phishing801
3d510977d60a44322f88100b515f06cb5ed83babc64247068d1a489595faa6c5sha256phishing801
b148626849c11dd5b3230632a38a6302hashransomware802
25b6fc4f9c54a28ba7bfc4dfeafb62c99b59ea6f0d17679219b876b321965095sha256phishing801
07cd03e2082bcb0b890cc59ce4c770d1a095ac6f1ae9cf999f5542555c56f841sha256phishing801
08060143ea9b55b480746b415af22e3ahashransomware801
15d1002d9935fbfc9dfc65eb70fe4ecc0943c784hashransomware801
164e322d6fbc62e254d73583acd7f39444c884d3f5e6a5d27db143fc25bc88b3sha256supply_chain801
221a39856b37e3c682f62427f1e6b965b36a2405764689c914672770a01a1fa9sha256801
f6669bd504ce6b0e303be7ee47f2ebbc062989c88c41f0a3f436044a24869798sha256supply_chain801
50ffce607867d8fa8eaf6ef5cd25a3c0e7e4415e881b9e55c04a67bcddb74fdfsha256supply_chain801
067ad6221b2224d5cdb64e51c5516132d820cf4d7edf9ec170643943e79c04b7sha256phishing801
01e3dce00ea45829bd9f6a583004976ac63973a0hashcryptojacking801
c8075bbff748096e1c6a1ea0aa67bb6762fdd7551427a12425b35b94c1f1ecf2sha256supply_chain801
833008c03d40422192051584d829d730497108bef31751cceb0cc043dd96bbfbsha256phishing801
d6f479736ba55d3c4e895c4940d035cf772f3192fb8dc496f09a801aed16d970sha256phishing801
8111edf01ac6cb5c77e249d4e84fd92a85b5e89c2e2bef92fbe00b6f1cc2aa8esha256phishing801
107b5aa3c4ef30b9b832e0a10b1efb1dcf433158bc6af8d890d66c0c9ed50d21sha256801

Showing the top 30 by severity of 5,738.