kevmap

Techniques › T1005

T1005 Data from Local System

collection — ESXi, Linux, macOS, Network Devices, Windows · attack.mitre.org · JSON

1
MITRE detection strategy
5
analytics
14
Sigma rules tagged attack.t1005
46
KEV CVEs mapped here
<p>Adversaries may search local system sources, such as file systems, configuration files, local databases, virtual machine files, or process memory, to find files of interest and sensitive data prior to Exfiltration.</p><p>Adversaries may do this using a Command and Scripting Interpreter, such as cmd as well as a Network Device CLI, which have functionality to interact with the file system to gather information. Adversaries may also use Automated Collection on the local system.</p>

KEV CVEs mapped to this technique · CTID Mappings Explorer

CVEVendor / productMapping typeStateAdded
CVE-2025-48928TeleMessage TM SGNL primary impact Mapped2025-07-01
CVE-2025-48927TeleMessage TM SGNL primary impact Mapped2025-07-01
CVE-2024-0769D-Link DIR-859 Router primary impact Mapped2025-06-25
CVE-2025-43200Apple Multiple Products secondary impact Mapped2025-06-16
CVE-2023-38950ZKTeco BioTime primary impact Mapped2025-05-19
CVE-2024-38475Apache HTTP Server primary impact Mapped2025-05-01
CVE-2024-53150Linux Kernel primary impact Mapped2025-04-09
CVE-2024-48248NAKIVO Backup and Replication primary impact Mapped2025-03-19
CVE-2025-24991Microsoft Windows primary impact Mapped2025-03-11
CVE-2025-22226VMware ESXi, Workstation, and Fusion primary impact Mapped2025-03-04
CVE-2024-50302Linux Kernel primary impact Mapped2025-03-04
CVE-2025-0111Palo Alto Networks PAN-OS primary impact Mapped2025-02-20
CVE-2025-21418Microsoft Windows primary impact Mapped2025-02-11
CVE-2024-55550Mitel MiCollab primary impact Mapped2025-01-07
CVE-2024-41713Mitel MiCollab primary impact Mapped2025-01-07
CVE-2024-5217ServiceNow Utah, Vancouver, and Washington DC Now Platform primary impact Mapped2024-07-29
CVE-2024-4879ServiceNow Utah, Vancouver, and Washington DC Now Platform primary impact Mapped2024-07-29
CVE-2024-34102Adobe Commerce and Magento Open Source secondary impact Mapped2024-07-17
CVE-2024-23692Rejetto HTTP File Server secondary impact Mapped2024-07-09
CVE-2024-24919Check Point Quantum Security Gateways primary impact Mapped2024-05-30
CVE-2024-4978Justice AV Solutions Viewer secondary impact Mapped2024-05-29
CVE-2023-49103ownCloud ownCloud graphapi primary impact Mapped2023-11-30
CVE-2023-4966Citrix NetScaler ADC and NetScaler Gateway primary impact Mapped2023-10-18
CVE-2023-38831RARLAB WinRAR secondary impact Mapped2023-08-24
CVE-2023-36884Microsoft Windows secondary impact Stale2023-07-17
CVE-2021-29256Arm Mali Graphics Processing Unit (GPU) secondary impact Mapped2023-07-07
CVE-2023-34362Progress MOVEit Transfer secondary impact Mapped2023-06-02
CVE-2021-26085Atlassian Confluence Server primary impact Mapped2022-03-28
CVE-2013-0629Adobe ColdFusion secondary impact Mapped2022-03-07
CVE-2017-11292Adobe Flash Player secondary impact Mapped2022-03-03
CVE-2021-27104Accellion FTA secondary impact Mapped2021-11-03
CVE-2021-27102Accellion FTA secondary impact Mapped2021-11-03
CVE-2021-27101Accellion FTA secondary impact Mapped2021-11-03
CVE-2021-27103Accellion FTA secondary impact Mapped2021-11-03
CVE-2017-5638Apache Struts secondary impact Mapped2021-11-03
CVE-2020-3452Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) primary impact Mapped2021-11-03
CVE-2019-1653Cisco Small Business RV320 and RV325 Routers secondary impact Mapped2021-11-03
CVE-2018-0296Cisco Adaptive Security Appliance (ASA) primary impact Mapped2021-11-03
CVE-2019-13608Citrix StoreFront Server secondary impact Mapped2021-11-03
CVE-2020-8193Citrix Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance primary impact Mapped2021-11-03
CVE-2020-8195Citrix Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance primary impact Mapped2021-11-03
CVE-2020-8196Citrix Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance secondary impact Mapped2021-11-03
CVE-2019-11634Citrix Workspace Application and Receiver for Windows secondary impact Mapped2021-11-03
CVE-2020-5902F5 BIG-IP secondary impact Stale2021-11-03
CVE-2019-5591Fortinet FortiOS secondary impact Mapped2021-11-03
CVE-2021-26855Microsoft Exchange Server secondary impact Mapped2021-11-03

Detection strategy · ATT&CK Enterprise v19.2

Sigma rules · SigmaHQ da9bb07d64, tag attack.t1005

Author: Swachchhanda Shrawan Poudel (Nextron Systems) · 2025-11-25 · logsource: product=windows category=process_creation · 0f60b28c-64dd-4e2c-9a63-5334d3e3a6e6
Detects a script interpreter process (like node.js or bun) spawning a known credential scanning tool (e.g., trufflehog, gitleaks). This behavior is indicative of an attempt to find and steal secrets, as seen in the "Shai-Hulud: The Second Coming" campaign.
Author: Roberto Rodriguez @Cyb3rWard0g · 2021-10-08 (modified 2023-11-30) · logsource: product=windows category=pipe_created · 1ea13e8c-03ea-409b-877d-ce5c3d2c1cb3
Detects suspicious local connections via a named pipe to the AD FS configuration database (Windows Internal Database). Used to access information such as the AD FS configuration settings which contains sensitive information used to sign SAML tokens.
Techniques: T1005
Author: Security Onion Solutions · 2024-03-08 · logsource: product=opencanary category=application · 22777c9e-873a-4b49-855f-6072ab861a52
Detects instances where an SMB service on an OpenCanary node has had a file open request.
Techniques: T1021T1005
Author: TropChaud · 2022-12-19 (modified 2023-01-19) · logsource: product=windows category=process_creation · 24c77512-782b-448a-8950-eddb0785fc71
Detect usage of the "sqlite" binary to query databases in Chromium-based browsers for potential data stealing.
Author: frack113 · 2021-08-16 (modified 2023-05-04) · logsource: product=windows category=process_creation · 2f47f1fd-0901-466e-a770-3b7092834a1b
Detects a command used by conti to dump database
Techniques: T1005
Author: frack113 · 2022-04-08 (modified 2023-01-19) · logsource: product=windows category=process_creation · 4833155a-4053-4c9c-a997-777fcea0baa7
Detect usage of the "sqlite" binary to query databases in Firefox and other Gecko-based browsers for potential data stealing.
Techniques: T1539T1005
Author: Diogo Braz · 2020-04-16 (modified 2022-10-05) · logsource: product=aws service=cloudtrail · 54b9a76a-3c71-4673-b4b3-2edb4566ea7b
An attempt to export an AWS EC2 instance has been detected. A VM Export might indicate an attempt to extract information from an instance.
Techniques: T1005T1537
Author: Nasreddine Bencherchali (Nextron Systems) · 2023-05-04 · logsource: product=windows category=process_creation · 696bfb54-227e-4602-ac5b-30d9d2053312
Detects potentially suspicious SQL queries using SQLCmd targeting the Veeam backup databases in order to steal information.
Techniques: T1005
Author: frack113 · 2022-02-13 (modified 2024-03-05) · logsource: product=windows category=process_creation · 6a69f62d-ce75-4b57-8dce-6351eb55b362
One way Qbot steals sensitive information is by extracting browser data from Internet Explorer and Microsoft Edge by using the built-in utility esentutl.exe
Techniques: T1005
Author: Jason Mull · 2025-05-12 · logsource: product=windows service=system · 882fbe50-d8d7-4e29-ae80-0648a8556866
Detects "BugCheck" errors indicating the system rebooted due to a crash, capturing the bugcheck code, dump file path, and report ID.
Techniques: T1003.002T1005
Author: frack113 · 2021-12-20 (modified 2023-02-13) · logsource: product=windows category=process_creation · b57ba453-b384-4ab9-9f40-1038086b4e53
Detects dump of credentials in VeeamBackup dbo
Techniques: T1005
Author: Austin Clark · 2019-08-11 (modified 2023-01-04) · logsource: product=cisco service=aaa · cd072b25-a418-4f98-8ebc-5093fb38fe1a
Collect pertinent data from the configuration files
Author: Swachchhanda Shrawan Poudel (Nextron Systems) · 2025-09-24 · logsource: product=linux category=process_creation · efd2eb09-b72e-4a61-8dc7-b1382a1e8983
Detects potential Shai Hulud NPM package attack attempting to exfiltrate data via curl to external webhook sites.
Techniques: T1041T1005
Author: Swachchhanda Shrawan Poudel (Nextron Systems) · 2025-11-25 · logsource: product=linux category=process_creation · f0025a69-e1b7-4dda-a53c-db21fa2d4071
Detects a script interpreter process (like node.js or bun) spawning a known credential scanning tool (e.g., trufflehog, gitleaks). This behavior is indicative of an attempt to find and steal secrets, as seen in the "Shai-Hulud: The Second Coming" campaign.