Clankerusecase
MITRE ATT&CK detection coverage
← Back to main site
Home/ MITRE Matrix/ Collection/ T1005

T1005Data from Local System

T1005 — Data from Local System is a MITRE ATT&CK technique in the Collection tactic. Clankerusecase tracks 28 detection use cases covering it and 65 threat-intel articles citing it.

Collection
View on the matrix → Filter Detection Library MITRE official spec ↗
28Use cases
65Articles
0Sub-techniques
1Tactic

Use cases covering this technique (28)

Crypto-wallet file/keystore access by non-wallet process Internal actions · alerting DSΣP [WEEKLY] Non-Browser Process Reads Browser Credential / Cookie SQLite Then Egresses to Public Destination Within 10 Minutes Internal actions · alerting DSPDD Cisco ASA - Device File Copy Activity ESCU actions · hunting P Cisco ASA - Device File Copy to Remote Location ESCU actions · hunting P ESXi Sensitive Files Accessed ESCU actions · alerting P ESXi VM Exported via Remote Tool ESCU actions · alerting P PTC Windchill Gateway Command Execution ESCU actions · hunting P Sqlite Module In Temp Folder ESCU actions · alerting P Cisco TFTP Server Configuration for Data Exfiltration ESCU actions · alerting P [LLM] Rails/libvips worker reading process environment or system secrets (CVE-2026-66066 file-read) Bespoke actions · alerting SΣPCS [LLM] File read/write/delete/rename performed by a goshs process (SFTP data access) Bespoke actions · hunting DSPDDCS [LLM] NightLedger recon: access to C:\Windows\debug\NetSetup.log by non-system process Bespoke actions · hunting DSPDDCS [LLM] MySQL server (mysqld) writes exfil file via SELECT INTO OUTFILE on Budibase DB host Bespoke actions · hunting DSΣPCS [LLM] BitLocker recovery key harvesting via manage-bde -protectors -get Bespoke actions · hunting DSΣPDDCS [LLM] Siemens ROX II xz utility misused as cat to read root-owned secrets (CVE-2025-40948) Bespoke actions · hunting DSΣDD [LLM] CastleStealer/Starland RAT accessing browser credential stores and crypto wallets Bespoke actions · hunting DSΣPDDCS [LLM] HelloExecutor recon enumerating ViPNet Client/Administrator Export key stores Bespoke recon · hunting DSΣPDDCS [LLM] Post-RCE read of DIRAC dirac.cfg / proxy / token stores on FileCatalog host Bespoke actions · hunting DSΣPDDCS [LLM] YesWiki credential access — web user reads wakka.config.php / .env / /etc/passwd Bespoke actions · hunting DSΣPDDCS [LLM] Cilium Envoy admin socket abuse: TLS secret / config disclosure via admin.sock (CVE-2026-49445) Bespoke actions · hunting DSΣPDDCS [LLM] macOS.Gaslight keychain theft + collected_data.zip staging Bespoke actions · alerting DSΣPCS [LLM] Rust build script harvesting git commit diff (onering build.rs) Bespoke actions · alerting DSΣPDDCS [LLM] Node/npm/Bun process enumerating cloud, wallet, AI, and messaging credential file paths Bespoke actions · hunting DSPDDCS [LLM] Non-browser process copying Chrome/Edge/Brave Login Data, Web Data, or wallet extension LevelDB state Bespoke actions · alerting DSΣPDDCS [LLM] AI session-log harvest via prompt-log extract.sh writing markdown with embedded secrets Bespoke actions · alerting DSΣPDDCS [LLM] Pistache binary theft via /doc/../../proc/self/exe path traversal Bespoke actions · alerting SΣP [LLM] curl --path-as-is traversal command exfiltrating /proc/self/exe or /etc/passwd Bespoke exploit · alerting DSΣPDDCS [LLM] Successful sensitive-file disclosure via st traversal (/etc/passwd, package-lock.json) Bespoke actions · alerting SΣP

Articles citing this technique (65)