Gold Open Source
ExplorePackagesVulnerabilitiesCWEsMCP ServersScan
Login
Gold Open Source

The authoritative source for production-ready open-source components. Every package, container image, AI model, and MCP server undergoes rigorous verification for security, malware, and license compliance.

Explore Gold

  • Explore Everything
  • Packages
  • Gold Certified Packages
  • Container Images
  • AI Models
  • MCP Servers
  • Agent Skills
  • Chip Manufacturers

Security Data & Tools

  • Scan Your Dependencies
  • Trending Threats
  • Threat RSS Feeds
  • CVE Database
  • Actively Exploited (KEV)
  • SGZ Zero-Days
  • CWE Index
  • MITRE ATT&CK
  • Malicious Packages
  • Security Glossary
  • Supply-Chain Report
  • Developers (API & Badge)
  • Chrome Extension
  • Credits & Data Sources

Products

  • The Platform
  • ESSCM
  • Portal
  • TPRM
  • OSM
  • Cowork
  • Code / Runner
  • Guard

Use Cases

  • Know Your Software
  • Auto-Fix Vulnerabilities
  • Asset Discovery
  • AI Governance
  • MCP Server Security
  • Supply Chain Compliance
  • Zero-Day Discovery
  • All Use Cases

Company

  • About
  • Pricing
  • Blog
  • Documentation
  • Safeguard Academy
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 Gold Open Source. All rights reserved.

Built with care bySafeguard
Home/ATT&CK/T1533
MITRE ATT&CK Technique

T1533: Data from Local System

ShareXLinkedInRedditHN

Adversaries may search local system sources, such as file systems or local databases, to find files of interest and sensitive data prior to exfiltration. Access to local system data, which includes information stored by the operating system, often requires escalated privileges. Examples of local system data include authentication tokens, the device keyboard cache, Wi-Fi passwords, and photos. On Android, adversaries may also attempt to access files from external storage which may require additional storage-related permissions.

Tactics
Collection
Platforms
Android, iOS

▪Used by groups (1)

G0112Windshift

▪Software using this technique (52)

S0290GooliganmalwareS0295RCSAndroidmalwareS0301DendroidmalwareS0305SpyNote RATmalwareS0328Stealth MangomalwareS0329TangelomalwareS0405ExodusmalwareS0406GustuffmalwareS0407MonoklemalwareS0408FlexiSpytoolS0418ViceLeakermalwareS0421GolfSpymalwareS0422AnubismalwareS0423GinpmalwareS0425Corona UpdatesmalwareS0426Concipit1248malwareS0427TrickMomalwareS0463INSOMNIAmalwareS0489WolfRATmalwareS0505Desert ScorpionmalwareS0506ViperRATmalwareS0507eSurvmalwareS0535Golden CupmalwareS0536GPlayedmalwareS0544HenBoxmalwareS0549SilkBeanmalwareS0550DoubleAgentmalwareS0551GoldenEaglemalwareS0555CHEMISTGAMESmalwareS0558Tiktok PromalwareS0577FrozenCellmalwareS0655BusyGaspermalwareS1054DrinikmalwareS1061AbstractEmumalwareS1069TangleBotmalwareS1077HornbillmalwareS1079BOULDSPYmalwareS1080FakecallsmalwareS1082SunbirdmalwareS1083ChameleonmalwareS1092EscobarmalwareS1094BRATAmalwareS1095AhRatmalwareS1126PhenakitemalwareS1185LightSpymalwareS1195SpyC23malwareS1215Binary ValidatormalwareS1216TriangleDBmalwareS1241RatMiladmalwareS1243DCHSpymalwareS9005DocSwapmalwareS9006VajraSpymalware

▪Reference

T1533on MITRE ATT&CK

MITRE ATT&CK® is a registered trademark of The MITRE Corporation. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.