Clankerusecase
MITRE ATT&CK detection coverage
← Back to main site
Home/ MITRE Matrix/ Collection/ T1005

T1005Data from Local System

T1005 — Data from Local System is a MITRE ATT&CK technique in the Collection tactic. Clankerusecase tracks 25 detection use cases covering it and 55 threat-intel articles citing it.

Collection
View on the matrix → Filter Detection Library MITRE official spec ↗
25Use cases
55Articles
0Sub-techniques
1Tactic

Use cases covering this technique (25)

Crypto-wallet file/keystore access by non-wallet process Internal actions · alerting DSΣP [WEEKLY] Non-Browser Process Reads Browser Credential / Cookie SQLite Then Egresses to Public Destination Within 10 Minutes Internal actions · alerting DSPDD Cisco ASA - Device File Copy Activity ESCU actions · hunting P Cisco ASA - Device File Copy to Remote Location ESCU actions · hunting P ESXi Sensitive Files Accessed ESCU actions · alerting P ESXi VM Exported via Remote Tool ESCU actions · alerting P PTC Windchill Gateway Command Execution ESCU actions · hunting P Sqlite Module In Temp Folder ESCU actions · alerting P Cisco TFTP Server Configuration for Data Exfiltration ESCU actions · alerting P [LLM] Still Sync Telegram tdata theft via non-Telegram process + SeBackupPrivilege abuse Bespoke actions · hunting DSΣPDDCS [LLM] Command line referencing Chrome Sync Data LevelDB passkey path (copy/stage for exfil) Bespoke actions · alerting DSΣPDDCS [LLM] anthropickit loot file '/tmp/runner_exfil.json' written to disk Bespoke actions · alerting DSΣPCS [LLM] Browser credential-store theft via OctLurk browser password decryptor Bespoke actions · hunting DSΣPCS [LLM] MySQL server (mysqld) writes exfil file via SELECT INTO OUTFILE on Budibase DB host Bespoke actions · hunting DSΣPCS [LLM] Siemens ROX II xz utility misused as cat to read root-owned secrets (CVE-2025-40948) Bespoke actions · hunting DSΣDD [LLM] CastleStealer/Starland RAT accessing browser credential stores and crypto wallets Bespoke actions · hunting DSΣPDDCS [LLM] Post-RCE read of DIRAC dirac.cfg / proxy / token stores on FileCatalog host Bespoke actions · hunting DSΣPDDCS [LLM] YesWiki credential access — web user reads wakka.config.php / .env / /etc/passwd Bespoke actions · hunting DSΣPDDCS [LLM] macOS.Gaslight keychain theft + collected_data.zip staging Bespoke actions · alerting DSΣPCS [LLM] Rust build script harvesting git commit diff (onering build.rs) Bespoke actions · alerting DSΣPDDCS [LLM] Node/npm/Bun process enumerating cloud, wallet, AI, and messaging credential file paths Bespoke actions · hunting DSPDDCS [LLM] AI session-log harvest via prompt-log extract.sh writing markdown with embedded secrets Bespoke actions · alerting DSΣPDDCS [LLM] Pistache binary theft via /doc/../../proc/self/exe path traversal Bespoke actions · alerting SΣP [LLM] curl --path-as-is traversal command exfiltrating /proc/self/exe or /etc/passwd Bespoke exploit · alerting DSΣPDDCS [LLM] Successful sensitive-file disclosure via st traversal (/etc/passwd, package-lock.json) Bespoke actions · alerting SΣP

Articles citing this technique (55)