T1005Data from Local System
T1005 — Data from Local System is a MITRE ATT&CK technique in the Collection tactic. Clankerusecase tracks 25 detection use cases covering it and 55 threat-intel articles citing it.
Collection
25Use cases
55Articles
0Sub-techniques
1Tactic
Use cases covering this technique (25)
Crypto-wallet file/keystore access by non-wallet process [WEEKLY] Non-Browser Process Reads Browser Credential / Cookie SQLite Then Egresses to Public Destination Within 10 Minutes Cisco ASA - Device File Copy Activity Cisco ASA - Device File Copy to Remote Location ESXi Sensitive Files Accessed ESXi VM Exported via Remote Tool PTC Windchill Gateway Command Execution Sqlite Module In Temp Folder Cisco TFTP Server Configuration for Data Exfiltration [LLM] Still Sync Telegram tdata theft via non-Telegram process + SeBackupPrivilege abuse [LLM] Command line referencing Chrome Sync Data LevelDB passkey path (copy/stage for exfil) [LLM] anthropickit loot file '/tmp/runner_exfil.json' written to disk [LLM] Browser credential-store theft via OctLurk browser password decryptor [LLM] MySQL server (mysqld) writes exfil file via SELECT INTO OUTFILE on Budibase DB host [LLM] Siemens ROX II xz utility misused as cat to read root-owned secrets (CVE-2025-40948) [LLM] CastleStealer/Starland RAT accessing browser credential stores and crypto wallets [LLM] Post-RCE read of DIRAC dirac.cfg / proxy / token stores on FileCatalog host [LLM] YesWiki credential access — web user reads wakka.config.php / .env / /etc/passwd [LLM] macOS.Gaslight keychain theft + collected_data.zip staging [LLM] Rust build script harvesting git commit diff (onering build.rs) [LLM] Node/npm/Bun process enumerating cloud, wallet, AI, and messaging credential file paths [LLM] AI session-log harvest via prompt-log extract.sh writing markdown with embedded secrets [LLM] Pistache binary theft via /doc/../../proc/self/exe path traversal [LLM] curl --path-as-is traversal command exfiltrating /proc/self/exe or /etc/passwd [LLM] Successful sensitive-file disclosure via st traversal (/etc/passwd, package-lock.json)Articles citing this technique (55)
crit [GHSA / CRITICAL] CVE-2026-73300: Budibase: SQL Injection via `multipleStatements: true` art-201
crit Begun, the Patch Wars have art-253
high Microsoft's durabletask package on PyPi Compromised. Mini Shai Hulud attacks again... again! art-469
crit Mini Shai-Hulud Is Back: npm Worm Hits over 160 Packages, including Mistral and Tanstack art-486
high "A Mini Shai-Hulud Has Appeared": Bun-Based Stealer Hits SAP @cap-js and mbt npm Packages art-515
crit ForceMemo: Hundreds of GitHub Python Repos Compromised via Account Takeover and Force-Push art-597