T1005Data from Local System
T1005 — Data from Local System is a MITRE ATT&CK technique in the Collection tactic. Clankerusecase tracks 28 detection use cases covering it and 65 threat-intel articles citing it.
Collection
28Use cases
65Articles
0Sub-techniques
1Tactic
Use cases covering this technique (28)
Crypto-wallet file/keystore access by non-wallet process [WEEKLY] Non-Browser Process Reads Browser Credential / Cookie SQLite Then Egresses to Public Destination Within 10 Minutes Cisco ASA - Device File Copy Activity Cisco ASA - Device File Copy to Remote Location ESXi Sensitive Files Accessed ESXi VM Exported via Remote Tool PTC Windchill Gateway Command Execution Sqlite Module In Temp Folder Cisco TFTP Server Configuration for Data Exfiltration [LLM] Rails/libvips worker reading process environment or system secrets (CVE-2026-66066 file-read) [LLM] File read/write/delete/rename performed by a goshs process (SFTP data access) [LLM] NightLedger recon: access to C:\Windows\debug\NetSetup.log by non-system process [LLM] MySQL server (mysqld) writes exfil file via SELECT INTO OUTFILE on Budibase DB host [LLM] BitLocker recovery key harvesting via manage-bde -protectors -get [LLM] Siemens ROX II xz utility misused as cat to read root-owned secrets (CVE-2025-40948) [LLM] CastleStealer/Starland RAT accessing browser credential stores and crypto wallets [LLM] HelloExecutor recon enumerating ViPNet Client/Administrator Export key stores [LLM] Post-RCE read of DIRAC dirac.cfg / proxy / token stores on FileCatalog host [LLM] YesWiki credential access — web user reads wakka.config.php / .env / /etc/passwd [LLM] Cilium Envoy admin socket abuse: TLS secret / config disclosure via admin.sock (CVE-2026-49445) [LLM] macOS.Gaslight keychain theft + collected_data.zip staging [LLM] Rust build script harvesting git commit diff (onering build.rs) [LLM] Node/npm/Bun process enumerating cloud, wallet, AI, and messaging credential file paths [LLM] Non-browser process copying Chrome/Edge/Brave Login Data, Web Data, or wallet extension LevelDB state [LLM] AI session-log harvest via prompt-log extract.sh writing markdown with embedded secrets [LLM] Pistache binary theft via /doc/../../proc/self/exe path traversal [LLM] curl --path-as-is traversal command exfiltrating /proc/self/exe or /etc/passwd [LLM] Successful sensitive-file disclosure via st traversal (/etc/passwd, package-lock.json)Articles citing this technique (65)
crit Critical Rails Flaw Could Let Unauthenticated Attackers Read Server Files via Image Uploads art-06
crit [GHSA / CRITICAL] GHSA-q6x4-v3qx-85qw: Budibase: SQL Injection via `multipleStatements: true` art-85
crit Begun, the Patch Wars have art-150
high Microsoft's durabletask package on PyPi Compromised. Mini Shai Hulud attacks again... again! art-423
crit Mini Shai-Hulud Is Back: npm Worm Hits over 160 Packages, including Mistral and Tanstack art-440
high "A Mini Shai-Hulud Has Appeared": Bun-Based Stealer Hits SAP @cap-js and mbt npm Packages art-471
crit ForceMemo: Hundreds of GitHub Python Repos Compromised via Account Takeover and Force-Push art-556