T1005Data from Local System
T1005 — Data from Local System is a MITRE ATT&CK technique in the Collection tactic. Clankerusecase tracks 18 detection use cases covering it and 58 threat-intel articles citing it.
Collection
18Use cases
58Articles
0Sub-techniques
1Tactic
Use cases covering this technique (18)
Crypto-wallet file/keystore access by non-wallet process [WEEKLY] Non-Browser Process Reads Browser Credential / Cookie SQLite Then Egresses to Public Destination Within 10 Minutes Cisco ASA - Device File Copy Activity Cisco ASA - Device File Copy to Remote Location ESXi Sensitive Files Accessed ESXi VM Exported via Remote Tool Sqlite Module In Temp Folder Cisco TFTP Server Configuration for Data Exfiltration [LLM] Non-forensic process bulk-reading the App.MenuItem Biome stream [LLM] High-volume scripted access to Tchap Matrix endpoint (bulk public-room scraping) [LLM] OpenClaw agent runtime reads secrets store (.env / .aws / id_rsa) followed by external network egress [LLM] Cargo build script spawning git with onering's exfil --pretty=format JSON [LLM] Node/npm/Bun process enumerating cloud, wallet, AI, and messaging credential file paths [LLM] Non-browser process copying Chrome/Edge/Brave Login Data, Web Data, or wallet extension LevelDB state [LLM] Inbound HTTP request bearing sidoraress backdoor x-operation operator tokens [LLM] s1ngularity collection artifact — `/tmp/inventory.txt` written by node/npm on runner [LLM] AI session-log harvest via prompt-log extract.sh writing markdown with embedded secrets [LLM] s1ngularity nx: /tmp/inventory.txt staging file created on hostArticles citing this technique (58)
high Microsoft's durabletask package on PyPi Compromised. Mini Shai Hulud attacks again... again! art-254
crit Mini Shai-Hulud Is Back: npm Worm Hits over 160 Packages, including Mistral and Tanstack art-315
high "A Mini Shai-Hulud Has Appeared": Bun-Based Stealer Hits SAP @cap-js and mbt npm Packages art-348
crit ForceMemo: Hundreds of GitHub Python Repos Compromised via Account Takeover and Force-Push art-434
crit Glassworm Is Back: A New Wave of Invisible Unicode Attacks Hits Hundreds of Repositories art-468