Applied Cybernetics Group
T1005 — Data from Local System
- Technique
T1005- Tactics
- Collection
- MISP citations
- 0
- KEV CVEs mapped
- 46
- Community rules
- 14
- thrunt rules
- 0
- Upstream
- https://attack.mitre.org/techniques/T1005
MITRE description
Adversaries may search local system sources, such as file systems, configuration files, local databases, virtual machine files, or process memory, to find files of interest and sensitive data prior to Exfiltration. Adversaries may do this using a [Command and Scripting Interpreter](https://attack.mitre.org/techniques/T1059), such as [cmd](https://attack.mitre.org/software/S0106) as well as a [Network Device CLI](https://attack.mitre.org/techniques/T1059/008), which have functionality to interact with the file system to gather information.(Citation: show_run_config_cmd_cisco) Adversaries may also use [Automated Collection](https://attack.mitre.org/techniques/T1119) on the local system.
KEV CVEs mapped to this technique
Per MITRE CTID's hand-curated KEV→ATT&CK mappings — these are the actively-exploited vulnerabilities behind this technique's KEV signal.
CVE-2025-48928CVE-2025-48927CVE-2025-43200CVE-2025-24991CVE-2025-22226CVE-2025-21418CVE-2025-0111CVE-2024-55550CVE-2024-53150CVE-2024-5217CVE-2024-50302CVE-2024-4978CVE-2024-4879CVE-2024-48248CVE-2024-41713CVE-2024-38475CVE-2024-34102CVE-2024-24919CVE-2024-23692CVE-2024-0769CVE-2023-4966CVE-2023-49103CVE-2023-38950CVE-2023-38831CVE-2023-36884CVE-2023-34362CVE-2021-29256CVE-2021-27104CVE-2021-27103CVE-2021-27102CVE-2021-27101CVE-2021-26855CVE-2021-26085CVE-2020-8196CVE-2020-8195CVE-2020-8193CVE-2020-5902CVE-2020-3452CVE-2019-5591CVE-2019-1653CVE-2019-13608CVE-2019-11634CVE-2018-0296CVE-2017-5638CVE-2017-11292CVE-2013-0629
Detection coverage
SigmaHQ community rules
- Potential Conti Ransomware Database Dumping Activity Via SQLCmd (emerging-threats)
- Shai-Hulud NPM Package Malicious Exfiltration via Curl (emerging-threats)
- OpenCanary - SMB File Open Request (core)
- AWS EC2 VM Export Failure (core)
- Script Interpreter Spawning Credential Scanner - Linux (core)
- Cisco Collect Data (core)
- Crash Dump Created By Operating System (core)
- ADFS Database Named Pipe Connection By Uncommon Tool (core)
- Esentutl Steals Browser Information (core)
- Veeam Backup Database Suspicious Query (core)
- VeeamBackup Database Credentials Dump Via Sqlcmd.EXE (core)
- SQLite Chromium Profile Data DB Access (core)
- SQLite Firefox Profile Data DB Access (core)
- Script Interpreter Spawning Credential Scanner - Windows (core)