Gold Open Source
ExplorePackagesVulnerabilitiesCWEsMCP ServersScan
Login
Gold Open Source

The authoritative source for production-ready open-source components. Every package, container image, AI model, and MCP server undergoes rigorous verification for security, malware, and license compliance.

Explore Gold

  • Explore Everything
  • Packages
  • Gold Certified Packages
  • Container Images
  • AI Models
  • MCP Servers
  • Agent Skills
  • Chip Manufacturers

Security Data & Tools

  • Scan Your Dependencies
  • Trending Threats
  • Threat RSS Feeds
  • CVE Database
  • Actively Exploited (KEV)
  • SGZ Zero-Days
  • CWE Index
  • MITRE ATT&CK
  • Malicious Packages
  • Security Glossary
  • Supply-Chain Report
  • Developers (API & Badge)
  • Chrome Extension
  • Credits & Data Sources

Products

  • The Platform
  • ESSCM
  • Portal
  • TPRM
  • OSM
  • Cowork
  • Code / Runner
  • Guard

Use Cases

  • Know Your Software
  • Auto-Fix Vulnerabilities
  • Asset Discovery
  • AI Governance
  • MCP Server Security
  • Supply Chain Compliance
  • Zero-Day Discovery
  • All Use Cases

Company

  • About
  • Pricing
  • Blog
  • Documentation
  • Safeguard Academy
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 Gold Open Source. All rights reserved.

Built with care bySafeguard
Home/ATT&CK/T1005
MITRE ATT&CK Technique

T1005: Data from Local System

ShareXLinkedInRedditHN

Adversaries may search local system sources, such as file systems, configuration files, local databases, virtual machine files, or process memory, to find files of interest and sensitive data prior to Exfiltration. Adversaries may do this using a [Command and Scripting Interpreter](https://attack.mitre.org/techniques/T1059), such as [cmd](https://attack.mitre.org/software/S0106) as well as a [Network Device CLI](https://attack.mitre.org/techniques/T1059/008), which have functionality to interact with the file system to gather information.(Citation: show_run_config_cmd_cisco) Adversaries may also use [Automated Collection](https://attack.mitre.org/techniques/T1119) on the local system.

Tactics
Collection
Platforms
ESXi, Linux, macOS, Network Devices, Windows

▪Mitigations (1)

M1057Data Loss Prevention

Data Loss Prevention (DLP) involves implementing strategies and technologies to identify, categorize, monitor, and control the movement of sensitive data within an organization. This includes protecting data formats indicative of Personally Identifiable Information (PII), intellectual property, or financial data from unauthorized access, transmission, or exfiltration. DLP solutions integrate with network, endpoint, and cloud platforms to enforce security policies and prevent accidental or malicious data leaks. (Citation: PurpleSec Data Loss Prevention) This mitigation can be implemented through the following measures: Sensitive Data Categorization: - Use Case: Identify and classify data based on sensitivity (e.g., PII, financial data, trade secrets). - Implementation: Use DLP solutions to scan and tag files containing sensitive information using predefined patterns, such as Social Security Numbers or credit card details. Exfiltration Restrictions: - Use Case: Prevent unauthorized transmission of sensitive data. - Implementation: Enforce policies to block unapproved email attachments, unauthorized USB usage, or unencrypted data uploads to cloud storage. Data-in-Transit Monitoring: - Use Case: Detect and prevent the transmission of sensitive data over unapproved channels. - Implementation: Deploy network-based DLP tools to inspect outbound traffic for sensitive content (e.g., financial records or PII) and block unapproved transmissions. Endpoint Data Protection: - Use Case: Monitor and control sensitive data usage on endpoints. - Implementation: Use endpoint-based DLP agents to block copy-paste actions of sensitive data and unauthorized printing or file sharing. Cloud Data Security: - Use Case: Protect data stored in cloud platforms. - Implementation: Integrate DLP with cloud storage platforms like Google Drive, OneDrive, or AWS to monitor and restrict sensitive data sharing or downloads.

▪Used by groups (45)

G0001AxiomG0004Ke3changG0006APT1G0007APT28G0010TurlaG0016APT29G0022APT3G0027Threat Group-3390G0032Lazarus GroupG0034Sandworm TeamG0035DragonflyG0037FIN6G0038Stealth FalconG0040PatchworkG0045menuPassG0046FIN7G0047Gamaredon GroupG0049OilRigG0059Magic HoundG0060BRONZE BUTLERG0067APT37G0070Dark CaracalG0082APT38G0087APT39G0093GALLIUMG0094KimsukyG0096APT41G0100InceptionG0102Wizard SpiderG0117Fox KittenG0124WindigoG0125HAFNIUMG0138AndarielG0143Aquatic PandaG1003Ember BearG1004LAPSUS$G1012CURIUMG1014LuminousMothG1016FIN13G1017Volt TyphoonG1022ToddyCatG1030AgriusG1039RedCurlG1054MirrorFaceG1055VOID MANTICORE

▪Software using this technique (169)

S0009HikitmalwareS0011TaidoormalwareS0012PoisonIvymalwareS0015IxeshemalwareS0020China ChoppermalwareS0022UroburosmalwareS0036FLASHFLOODmalwareS0048PinchDukemalwareS0050CosmicDukemalwareS0079MobileOrdermalwareS0083MisdatmalwareS0084Mis-TypemalwareS0090RovermalwareS0115CrimsonmalwareS0128BADNEWSmalwareS0154Cobalt StrikemalwareS0169RawPOSmalwareS0193ForfilestoolS0194PowerSploittoolS0197PUNCHTRACKmalwareS0203HydraqmalwareS0208PasammalwareS0211LinfomalwareS0223POWERSTATSmalwareS0234BandookmalwareS0237GravityRATmalwareS0238ProxysvcmalwareS0239BankshotmalwareS0240ROKRATmalwareS0248ytymalwareS0250KoadictoolS0260InvisiMolemalwareS0262QuasarRATtoolS0265KazuarmalwareS0266TrickBotmalwareS0268BisonalmalwareS0274CalistomalwareS0275UPPERCUTmalwareS0337BadPatchmalwareS0340OctopusmalwareS0352OSX_OCEANLOTUS.DmalwareS0356KONNImalwareS0381FlawedAmmyymalwareS0385njRATmalwareS0386UrsnifmalwareS0395LightNeuronmalwareS0404esentutltoolS0409MachetemalwareS0412ZxShellmalwareS0444ShimRatmalwareS0448Rising SunmalwareS0452USBferrymalwareS0458RamsaymalwareS0461SDBbotmalwareS0467TajMahalmalwareS0477GoopymalwareS0492CookieMinermalwareS0498CryptoisticmalwareS0500MCMDtoolS0502DrovorubmalwareS0503FrameworkPOSmalwareS0512FatDukemalwareS0514WellMessmalwareS0515WellMailmalwareS0517PillowmintmalwareS0520BLINDINGCANmalwareS0526KGH_SPYmalwareS0533SLOTHFULMEDIAmalwareS0534BazarmalwareS0538CrutchmalwareS0559SUNBURSTmalwareS0564BlackMouldmalwareS0567DtrackmalwareS0572Caterpillar WebShellmalwareS0594Out1toolS0598P.A.S. WebshellmalwareS0610SideTwistmalwareS0615SombRATmalwareS0622AppleSeedmalwareS0629RainyDaymalwareS0630NebulaemalwareS0632GrimAgentmalwareS0634EnvyScoutmalwareS0642BADFLICKmalwareS0645WevtutiltoolS0646SpicyOmelettemalwareS0650QakBotmalwareS0651BoxCaonmalwareS0652MarkiRATmalwareS0653xCaonmalwareS0658XCSSETmalwareS0660ClamblingmalwareS0661FoggyWebmalwareS0662RCSessionmalwareS0663SysUpdatemalwareS0665ThreatNeedlemalwareS0666GelsemiummalwareS0667ChrommmemalwareS0668TinyTurlamalwareS0670WarzoneRATmalwareS0671TomirismalwareS0672ZoxmalwareS0673DarkWatchmanmalwareS0674CharmPowermalwareS0686QuietSievemalwareS0687Cyclops BlinkmalwareS0690Green LambertmalwareS0691NeoichormalwareS0694DRATzarusmalwareS0696FlagpromalwareS1012PowerLessmalwareS1013ZxxZmalwareS1014DanBotmalwareS1015MilanmalwareS1016MacMamalwareS1017OutSteelmalwareS1018Saint BotmalwareS1019SharkmalwareS1020KevinmalwareS1021DnsSystemmalwareS1022IceApplemalwareS1023CreepyDrivemalwareS1025AmadeymalwareS1026MongallmalwareS1028Action RATmalwareS1029AuTo StealermalwareS1031PingPullmalwareS1034StrifeWatermalwareS1037STARWHALEmalwareS1039BumblebeemalwareS1043ccf32malwareS1044FunnyDreammalwareS1050PcSharetoolS1059metaMainmalwareS1060MafaldamalwareS1063Brute Ratel C4toolS1064SVCReadymalwareS1065Woody RATmalwareS1075KOPILUWAKmalwareS1085SardonicmalwareS1089SharpDiscomalwareS1090NightClubmalwareS1099SamuraimalwareS1101LoFiSemalwareS1102PcextermalwareS1110SLIGHTPULSEmalwareS1111DarkGatemalwareS1113RAPIDPULSEmalwareS1131NPPSPYtoolS1132IPsec HelpermalwareS1146MgBotmalwareS1148Raccoon StealermalwareS1149CHIMNEYSWEEPmalwareS1159DUSTTRAPmalwareS1160LatrodectusmalwareS1196Troll StealermalwareS1200StealBitmalwareS1224CASTLETAPmalwareS1229HavocmalwareS1240RedLine StealermalwareS1245InvisibleFerretmalwareS1246BeaverTailmalwareS9009TruffleHogtoolS9010GlassWormmalwareS9015BRICKSTORMmalwareS9020LODEINFOmalwareS9023HiddenFacemalwareS9024SPAWNCHIMERAmalwareS9035LAMEHUGmalware

▪Reference

T1005on MITRE ATT&CK

MITRE ATT&CK® is a registered trademark of The MITRE Corporation. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.