Cross-source coverage
T1005 / ATT&CK
Data from Local System
161 rules · 154 families across 11 sources.
70 deprecated hidden · include 11 atomic-IOC hidden · include
From MITRE ATT&CK 19.2
Adversaries may search local system sources, such as file systems, configuration files, local databases, virtual machine files, or process memory, to find files of interest and sensitive data prior to Exfiltration.
Adversaries may do this using a Command and Scripting Interpreter, such as cmd as well as a Network Device CLI, which have functionality to interact with the file system to gather information. Adversaries may also use Automated Collection on the local system.
- Tactics
- Collection
- Platforms
- ESXi · Linux · macOS · Network Devices · Windows
- Telemetry
-
WinEventLog:SecurityWinEventLog:Sysmonauditd:SYSCALLmacos:unifiedlogfs:fsusagenetworkdevice:cliesxis:vmkernelesxi:hostd
How MITRE says to detect it DET0380
Detection of Local Data Collection Prior to Exfiltration
Windows Analytic 1070
Adversaries collecting local files via PowerShell, WMI, or direct file API calls often include recursive file listings, targeted file reads, and temporary file staging.
WinEventLog:SecurityEventCode=4688WinEventLog:SysmonEventCode=11
Linux Analytic 1071
Adversaries using bash scripts or tools to recursively enumerate user home directories, config files, or SSH keys.
auditd:SYSCALLopenauditd:SYSCALLexecve
macOS Analytic 1072
Adversary use of bash/zsh or AppleScript to locate files and exfil targets like user keychains or documents.
macos:unifiedlogprocess:spawnfs:fsusageread/write
Network Devices Analytic 1073
Collection of device configuration via CLI commands (e.g., `show running-config`, `copy flash`, `more`), often followed by TFTP/SCP transfers.
networkdevice:clicommand logging
ESXi Analytic 1074
Adversaries accessing datastore or configuration files via `vim-cmd`, `esxcli`, or SCP to extract logs, VMs, or host configurations.
esxis:vmkernelDatastore Accessesxi:hostdCommand Execution
Emerging Threats Open
88 rules · 82 families| Detection | Severity | Format |
|---|---|---|
| ET HUNTING Suspicious Zipped Filename in Outbound POST Request (ccdata.txt) M1 2 variants | High | Suricata |
| ET HUNTING Suspicious Zipped Filename in Outbound POST Request (ccdata.txt) M2 2 variants | High | Suricata |
| ET HUNTING Suspicious Zipped Filename in Outbound POST Request (cookie.txt) M1 2 variants | High | Suricata |
| ET HUNTING Suspicious Zipped Filename in Outbound POST Request (cookie.txt) M2 2 variants | High | Suricata |
| ET MALWARE [ANY.RUN] RedLine Stealer/MetaStealer Family Related (MC-NMF Authorization) | High | Suricata |
| ET MALWARE [ANY.RUN] RisePro TCP (Activity) | High | Suricata |
| ET MALWARE [ANY.RUN] RisePro TCP (Exfiltration) | High | Suricata |
| ET MALWARE [ANY.RUN] RisePro TCP (External IP) | High | Suricata |
| ET MALWARE [ANY.RUN] RisePro TCP (Token) | High | Suricata |
| ET MALWARE [ANY.RUN] RisePro TCP v.0.x (Get_settings) | High | Suricata |
+ 78 more from Emerging Threats Open → showing the 10 highest-severity
elastic/detection-rules
32 rules| Detection | Severity | Format |
|---|---|---|
| AWS Credentials Searched For Inside A Container | High | Elastic TOML |
| GenAI Process Accessing Sensitive Files | High | Elastic TOML |
| Linux init (PID 1) Secret Dump via GDB | High | Elastic TOML |
| Manual Memory Dumping via Proc Filesystem | High | Elastic TOML |
| Potential Linux Credential Dumping via Unshadow | High | Elastic TOML |
| Potential Privacy Control Bypass via Localhost Secure Copy | High | Elastic TOML |
| Sensitive File Access followed by Compression | High | Elastic TOML |
| Sensitive Files Compression Inside A Container | High | Elastic TOML |
| Suspicious TCC Access Granted for User Folders | High | Elastic TOML |
| Suspicious Web Browser Sensitive File Access | High | Elastic TOML |
+ 22 more from elastic/detection-rules → showing the 10 highest-severity
SigmaHQ/sigma
14 rules| Detection | Severity | Format |
|---|---|---|
| OpenCanary - SMB File Open Request | High | Sigma |
| Potential Conti Ransomware Database Dumping Activity Via SQLCmd | High | Sigma |
| Script Interpreter Spawning Credential Scanner - Linux | High | Sigma |
| Script Interpreter Spawning Credential Scanner - Windows | High | Sigma |
| Shai-Hulud NPM Package Malicious Exfiltration via Curl | High | Sigma |
| SQLite Chromium Profile Data DB Access | High | Sigma |
| SQLite Firefox Profile Data DB Access | High | Sigma |
| VeeamBackup Database Credentials Dump Via Sqlcmd.EXE | High | Sigma |
| ADFS Database Named Pipe Connection By Uncommon Tool | Medium | Sigma |
| Crash Dump Created By Operating System | Medium | Sigma |
+ 4 more from SigmaHQ/sigma → showing the 10 highest-severity
socfortress/Wazuh-Rules
8 rules · 7 familiessplunk/security_content
7 rules| Detection | Severity | Format |
|---|---|---|
| Cisco ASA - Device File Copy Activity | Undefined | SPL |
| Cisco ASA - Device File Copy to Remote Location | Undefined | SPL |
| Cisco TFTP Server Configuration for Data Exfiltration | Undefined | SPL |
| ESXi Sensitive Files Accessed | Undefined | SPL |
| ESXi VM Exported via Remote Tool | Undefined | SPL |
| PTC Windchill Gateway Command Execution | Undefined | SPL |
| Sqlite Module In Temp Folder | Undefined | SPL |
Azure/Azure-Sentinel
4 rules| Detection | Severity | Format |
|---|---|---|
| AD FS Database Local SQL Statements | Medium | KQL |
| ADFS DKM Master Key Export | Medium | KQL |
| Microsoft Entra ID Health Monitoring Agent Registry Keys Access | Medium | KQL |
| Microsoft Entra ID Health Service Agents Registry Keys Access | Medium | KQL |
Bert-JanP/Hunting-Queries-Detection-Rules
2 rules| Detection | Severity | Format |
|---|---|---|
| 'File From Host Collected via Portal or Live Response | Undefined | KQL |
| MITRE ATT&CK Mapping | Undefined | KQL |
chronicle/detection-rules
2 rules| Detection | Severity | Format |
|---|---|---|
| sap_sensitive_tables_direct_access_by_rfc_logon_data_table | High | YARA-L |
| sap_sensitive_tables_direct_access_by_rfc_logon_static_list | High | YARA-L |
elastic/protections-artifacts
2 rules| Detection | Severity | Format |
|---|---|---|
| Sensitive File Access via Rsync | Undefined | Elastic TOML |
| Sensitive File Copy via Ditto | Undefined | Elastic TOML |
Wazuh Core Ruleset
1 rule| Detection | Severity | Format |
|---|---|---|
| Windows Security error event | Low | Wazuh XML |
falcosecurity/rules
1 rule| Detection | Severity | Format |
|---|---|---|
| Read ssh information | High | Falco YAML |