Techniques › T1005
T1005 Data from Local System
collection — ESXi, Linux, macOS, Network Devices, Windows · attack.mitre.org · JSON
1
MITRE detection strategy
5
analytics
14
Sigma rules tagged attack.t1005
46
KEV CVEs mapped here
<p>Adversaries may search local system sources, such as file systems, configuration files, local databases, virtual machine files, or process memory, to find files of interest and sensitive data prior to Exfiltration.</p><p>Adversaries may do this using a Command and Scripting Interpreter, such as cmd as well as a Network Device CLI, which have functionality to interact with the file system to gather information. Adversaries may also use Automated Collection on the local system.</p>
KEV CVEs mapped to this technique · CTID Mappings Explorer
| CVE | Vendor / product | Mapping type | State | Added |
|---|---|---|---|---|
| CVE-2025-48928 | TeleMessage TM SGNL | primary impact | Mapped | 2025-07-01 |
| CVE-2025-48927 | TeleMessage TM SGNL | primary impact | Mapped | 2025-07-01 |
| CVE-2024-0769 | D-Link DIR-859 Router | primary impact | Mapped | 2025-06-25 |
| CVE-2025-43200 | Apple Multiple Products | secondary impact | Mapped | 2025-06-16 |
| CVE-2023-38950 | ZKTeco BioTime | primary impact | Mapped | 2025-05-19 |
| CVE-2024-38475 | Apache HTTP Server | primary impact | Mapped | 2025-05-01 |
| CVE-2024-53150 | Linux Kernel | primary impact | Mapped | 2025-04-09 |
| CVE-2024-48248 | NAKIVO Backup and Replication | primary impact | Mapped | 2025-03-19 |
| CVE-2025-24991 | Microsoft Windows | primary impact | Mapped | 2025-03-11 |
| CVE-2025-22226 | VMware ESXi, Workstation, and Fusion | primary impact | Mapped | 2025-03-04 |
| CVE-2024-50302 | Linux Kernel | primary impact | Mapped | 2025-03-04 |
| CVE-2025-0111 | Palo Alto Networks PAN-OS | primary impact | Mapped | 2025-02-20 |
| CVE-2025-21418 | Microsoft Windows | primary impact | Mapped | 2025-02-11 |
| CVE-2024-55550 | Mitel MiCollab | primary impact | Mapped | 2025-01-07 |
| CVE-2024-41713 | Mitel MiCollab | primary impact | Mapped | 2025-01-07 |
| CVE-2024-5217 | ServiceNow Utah, Vancouver, and Washington DC Now Platform | primary impact | Mapped | 2024-07-29 |
| CVE-2024-4879 | ServiceNow Utah, Vancouver, and Washington DC Now Platform | primary impact | Mapped | 2024-07-29 |
| CVE-2024-34102 | Adobe Commerce and Magento Open Source | secondary impact | Mapped | 2024-07-17 |
| CVE-2024-23692 | Rejetto HTTP File Server | secondary impact | Mapped | 2024-07-09 |
| CVE-2024-24919 | Check Point Quantum Security Gateways | primary impact | Mapped | 2024-05-30 |
| CVE-2024-4978 | Justice AV Solutions Viewer | secondary impact | Mapped | 2024-05-29 |
| CVE-2023-49103 | ownCloud ownCloud graphapi | primary impact | Mapped | 2023-11-30 |
| CVE-2023-4966 | Citrix NetScaler ADC and NetScaler Gateway | primary impact | Mapped | 2023-10-18 |
| CVE-2023-38831 | RARLAB WinRAR | secondary impact | Mapped | 2023-08-24 |
| CVE-2023-36884 | Microsoft Windows | secondary impact | Stale | 2023-07-17 |
| CVE-2021-29256 | Arm Mali Graphics Processing Unit (GPU) | secondary impact | Mapped | 2023-07-07 |
| CVE-2023-34362 | Progress MOVEit Transfer | secondary impact | Mapped | 2023-06-02 |
| CVE-2021-26085 | Atlassian Confluence Server | primary impact | Mapped | 2022-03-28 |
| CVE-2013-0629 | Adobe ColdFusion | secondary impact | Mapped | 2022-03-07 |
| CVE-2017-11292 | Adobe Flash Player | secondary impact | Mapped | 2022-03-03 |
| CVE-2021-27104 | Accellion FTA | secondary impact | Mapped | 2021-11-03 |
| CVE-2021-27102 | Accellion FTA | secondary impact | Mapped | 2021-11-03 |
| CVE-2021-27101 | Accellion FTA | secondary impact | Mapped | 2021-11-03 |
| CVE-2021-27103 | Accellion FTA | secondary impact | Mapped | 2021-11-03 |
| CVE-2017-5638 | Apache Struts | secondary impact | Mapped | 2021-11-03 |
| CVE-2020-3452 | Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) | primary impact | Mapped | 2021-11-03 |
| CVE-2019-1653 | Cisco Small Business RV320 and RV325 Routers | secondary impact | Mapped | 2021-11-03 |
| CVE-2018-0296 | Cisco Adaptive Security Appliance (ASA) | primary impact | Mapped | 2021-11-03 |
| CVE-2019-13608 | Citrix StoreFront Server | secondary impact | Mapped | 2021-11-03 |
| CVE-2020-8193 | Citrix Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance | primary impact | Mapped | 2021-11-03 |
| CVE-2020-8195 | Citrix Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance | primary impact | Mapped | 2021-11-03 |
| CVE-2020-8196 | Citrix Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance | secondary impact | Mapped | 2021-11-03 |
| CVE-2019-11634 | Citrix Workspace Application and Receiver for Windows | secondary impact | Mapped | 2021-11-03 |
| CVE-2020-5902 | F5 BIG-IP | secondary impact | Stale | 2021-11-03 |
| CVE-2019-5591 | Fortinet FortiOS | secondary impact | Mapped | 2021-11-03 |
| CVE-2021-26855 | Microsoft Exchange Server | secondary impact | Mapped | 2021-11-03 |
Detection strategy · ATT&CK Enterprise v19.2
- DET0380 Detection of Local Data Collection Prior to Exfiltration v1.0
AN1070 WindowsAdversaries collecting local files via PowerShell, WMI, or direct file API calls often include recursive file listings, targeted file reads, and temporary file staging.Tunable:
TargetFilePathRegexParentProcessFilterAN1071 LinuxAdversaries using bash scripts or tools to recursively enumerate user home directories, config files, or SSH keys.Tunable:TimeWindowScriptToolNameAN1072 macOSAdversary use of bash/zsh or AppleScript to locate files and exfil targets like user keychains or documents.Tunable:UserContextTargetVolumeAN1073 Network DevicesCollection of device configuration via CLI commands (e.g.,show running-config,copy flash,more), often followed by TFTP/SCP transfers.Tunable:CommandScopeAuthenticatedUserListAN1074 ESXiAdversaries accessing datastore or configuration files viavim-cmd,esxcli, or SCP to extract logs, VMs, or host configurations.Tunable:AccessPathRegexInteractiveShellUsage
Sigma rules · SigmaHQ da9bb07d64, tag attack.t1005
Author: Swachchhanda Shrawan Poudel (Nextron Systems)
· 2025-11-25 · logsource: product=windows category=process_creation · 0f60b28c-64dd-4e2c-9a63-5334d3e3a6e6
Detects a script interpreter process (like node.js or bun) spawning a known credential scanning tool (e.g., trufflehog, gitleaks).
This behavior is indicative of an attempt to find and steal secrets, as seen in the "Shai-Hulud: The Second Coming" campaign.
Author: Roberto Rodriguez @Cyb3rWard0g
· 2021-10-08 (modified 2023-11-30) · logsource: product=windows category=pipe_created · 1ea13e8c-03ea-409b-877d-ce5c3d2c1cb3
Detects suspicious local connections via a named pipe to the AD FS configuration database (Windows Internal Database).
Used to access information such as the AD FS configuration settings which contains sensitive information used to sign SAML tokens.
Author: Security Onion Solutions
· 2024-03-08 · logsource: product=opencanary category=application · 22777c9e-873a-4b49-855f-6072ab861a52
Detects instances where an SMB service on an OpenCanary node has had a file open request.
Author: TropChaud
· 2022-12-19 (modified 2023-01-19) · logsource: product=windows category=process_creation · 24c77512-782b-448a-8950-eddb0785fc71
Detect usage of the "sqlite" binary to query databases in Chromium-based browsers for potential data stealing.
Author: frack113
· 2021-08-16 (modified 2023-05-04) · logsource: product=windows category=process_creation · 2f47f1fd-0901-466e-a770-3b7092834a1b
Detects a command used by conti to dump database
Author: frack113
· 2022-04-08 (modified 2023-01-19) · logsource: product=windows category=process_creation · 4833155a-4053-4c9c-a997-777fcea0baa7
Detect usage of the "sqlite" binary to query databases in Firefox and other Gecko-based browsers for potential data stealing.
Author: Diogo Braz
· 2020-04-16 (modified 2022-10-05) · logsource: product=aws service=cloudtrail · 54b9a76a-3c71-4673-b4b3-2edb4566ea7b
An attempt to export an AWS EC2 instance has been detected. A VM Export might indicate an attempt to extract information from an instance.
Author: Nasreddine Bencherchali (Nextron Systems)
· 2023-05-04 · logsource: product=windows category=process_creation · 696bfb54-227e-4602-ac5b-30d9d2053312
Detects potentially suspicious SQL queries using SQLCmd targeting the Veeam backup databases in order to steal information.
Author: frack113
· 2022-02-13 (modified 2024-03-05) · logsource: product=windows category=process_creation · 6a69f62d-ce75-4b57-8dce-6351eb55b362
One way Qbot steals sensitive information is by extracting browser data from Internet Explorer and Microsoft Edge by using the built-in utility esentutl.exe
Author: Jason Mull
· 2025-05-12 · logsource: product=windows service=system · 882fbe50-d8d7-4e29-ae80-0648a8556866
Detects "BugCheck" errors indicating the system rebooted due to a crash, capturing the bugcheck code, dump file path, and report ID.
Author: frack113
· 2021-12-20 (modified 2023-02-13) · logsource: product=windows category=process_creation · b57ba453-b384-4ab9-9f40-1038086b4e53
Detects dump of credentials in VeeamBackup dbo
Author: Austin Clark
· 2019-08-11 (modified 2023-01-04) · logsource: product=cisco service=aaa · cd072b25-a418-4f98-8ebc-5093fb38fe1a
Collect pertinent data from the configuration files
Author: Swachchhanda Shrawan Poudel (Nextron Systems)
· 2025-09-24 · logsource: product=linux category=process_creation · efd2eb09-b72e-4a61-8dc7-b1382a1e8983
Detects potential Shai Hulud NPM package attack attempting to exfiltrate data via curl to external webhook sites.
Author: Swachchhanda Shrawan Poudel (Nextron Systems)
· 2025-11-25 · logsource: product=linux category=process_creation · f0025a69-e1b7-4dda-a53c-db21fa2d4071
Detects a script interpreter process (like node.js or bun) spawning a known credential scanning tool (e.g., trufflehog, gitleaks).
This behavior is indicative of an attempt to find and steal secrets, as seen in the "Shai-Hulud: The Second Coming" campaign.