Cross-source coverage

T1005 / ATT&CK

Data from Local System

231 rules · 213 families across 11 sources.

11 atomic-IOC hidden · include

Showing deprecated rules · back to the default

From MITRE ATT&CK 19.2

Adversaries may search local system sources, such as file systems, configuration files, local databases, virtual machine files, or process memory, to find files of interest and sensitive data prior to Exfiltration.

Adversaries may do this using a Command and Scripting Interpreter, such as cmd as well as a Network Device CLI, which have functionality to interact with the file system to gather information. Adversaries may also use Automated Collection on the local system.

Tactics
Collection
Platforms
ESXi · Linux · macOS · Network Devices · Windows
Telemetry
WinEventLog:SecurityWinEventLog:Sysmonauditd:SYSCALLmacos:unifiedlogfs:fsusagenetworkdevice:cliesxis:vmkernelesxi:hostd

How MITRE says to detect it DET0380

Detection of Local Data Collection Prior to Exfiltration

Windows Analytic 1070

Adversaries collecting local files via PowerShell, WMI, or direct file API calls often include recursive file listings, targeted file reads, and temporary file staging.

  • WinEventLog:Security EventCode=4688
  • WinEventLog:Sysmon EventCode=11

Linux Analytic 1071

Adversaries using bash scripts or tools to recursively enumerate user home directories, config files, or SSH keys.

  • auditd:SYSCALL open
  • auditd:SYSCALL execve

macOS Analytic 1072

Adversary use of bash/zsh or AppleScript to locate files and exfil targets like user keychains or documents.

  • macos:unifiedlog process:spawn
  • fs:fsusage read/write

Network Devices Analytic 1073

Collection of device configuration via CLI commands (e.g., `show running-config`, `copy flash`, `more`), often followed by TFTP/SCP transfers.

  • networkdevice:cli command logging

ESXi Analytic 1074

Adversaries accessing datastore or configuration files via `vim-cmd`, `esxcli`, or SCP to extract logs, VMs, or host configurations.

  • esxis:vmkernel Datastore Access
  • esxi:hostd Command Execution

Emerging Threats Open

154 rules · 137 families
Detection Severity Format
ET DELETED Searchmeup Spyware Install (toolbar) High Suricata
ET DELETED thebestsoft4u.com Spyware Install (3) High Suricata
ET DELETED Virtumonde Spyware Information Post High Suricata
ET DELETED Virtumonde Spyware siae3123.exe GET 2 variants High Suricata
ET DELETED Virtumonde Spyware siae3123.exe GET (8081) 2 variants High Suricata
ET HUNTING Suspicious Zipped Filename in Outbound POST Request (ccdata.txt) M1 2 variants High Suricata
ET HUNTING Suspicious Zipped Filename in Outbound POST Request (ccdata.txt) M2 2 variants High Suricata
ET HUNTING Suspicious Zipped Filename in Outbound POST Request (cookie.txt) M1 2 variants High Suricata
ET HUNTING Suspicious Zipped Filename in Outbound POST Request (cookie.txt) M2 2 variants High Suricata
ET MALWARE [ANY.RUN] RedLine Stealer/MetaStealer Family Related (MC-NMF Authorization) High Suricata

+ 144 more from Emerging Threats Open → showing the 10 highest-severity

elastic/detection-rules

33 rules
Detection Severity Format
AWS Credentials Searched For Inside A Container High Elastic TOML
GenAI Process Accessing Sensitive Files High Elastic TOML
Linux init (PID 1) Secret Dump via GDB High Elastic TOML
Manual Memory Dumping via Proc Filesystem High Elastic TOML
Potential Linux Credential Dumping via Unshadow High Elastic TOML
Potential Privacy Control Bypass via Localhost Secure Copy High Elastic TOML
Sensitive File Access followed by Compression High Elastic TOML
Sensitive Files Compression Inside A Container High Elastic TOML
Suspicious TCC Access Granted for User Folders High Elastic TOML
Suspicious Web Browser Sensitive File Access High Elastic TOML

+ 23 more from elastic/detection-rules → showing the 10 highest-severity

SigmaHQ/sigma

14 rules
Detection Severity Format
OpenCanary - SMB File Open Request High Sigma
Potential Conti Ransomware Database Dumping Activity Via SQLCmd High Sigma
Script Interpreter Spawning Credential Scanner - Linux High Sigma
Script Interpreter Spawning Credential Scanner - Windows High Sigma
Shai-Hulud NPM Package Malicious Exfiltration via Curl High Sigma
SQLite Chromium Profile Data DB Access High Sigma
SQLite Firefox Profile Data DB Access High Sigma
VeeamBackup Database Credentials Dump Via Sqlcmd.EXE High Sigma
ADFS Database Named Pipe Connection By Uncommon Tool Medium Sigma
Crash Dump Created By Operating System Medium Sigma

+ 4 more from SigmaHQ/sigma → showing the 10 highest-severity

socfortress/Wazuh-Rules

8 rules · 7 families
Detection Severity Format
Sysmon - Event 1: Process creation · Data from Local System (T1005) 2 variants High Wazuh XML
Sysmon - Event 1: Process creation · PowerShell Compress-Archive (T1005) High Wazuh XML
Sysmon - Event 1: Process creation · PowerShell File Search (T1005) High Wazuh XML
Suspicious file scan: SQLite file header inspection and conditional bash execution Medium Wazuh XML
Sysmon - Event 12: RegistryEvent (Object create and delete) by · Data from Local System (T1005) Low Wazuh XML
Sysmon - Event 13: RegistryEvent (Value Set) by · Data from Local System (T1005) Low Wazuh XML
Sysmon - Event 14: RegistryEvent (Key and Value Rename) by · Data from Local System (T1005) Low Wazuh XML
Sysmon - Event 1: Process creation · Data from Local System (T1005) 2 variants Low Wazuh XML

splunk/security_content

7 rules
Detection Severity Format
Cisco ASA - Device File Copy Activity Undefined SPL
Cisco ASA - Device File Copy to Remote Location Undefined SPL
Cisco TFTP Server Configuration for Data Exfiltration Undefined SPL
ESXi Sensitive Files Accessed Undefined SPL
ESXi VM Exported via Remote Tool Undefined SPL
PTC Windchill Gateway Command Execution Undefined SPL
Sqlite Module In Temp Folder Undefined SPL

chronicle/detection-rules

5 rules
Detection Severity Format
sap_sensitive_tables_direct_access_by_rfc_logon_data_table High YARA-L
sap_sensitive_tables_direct_access_by_rfc_logon_static_list High YARA-L
fallout_rig_ek_delivers_raccoon_stealer Undefined YARA-L
godlua_malware_detector_sysmon_behavior Undefined YARA-L
mssql_server_backdoor_detection_vollgar Undefined YARA-L

Azure/Azure-Sentinel

4 rules
Detection Severity Format
AD FS Database Local SQL Statements Medium KQL
ADFS DKM Master Key Export Medium KQL
Microsoft Entra ID Health Monitoring Agent Registry Keys Access Medium KQL
Microsoft Entra ID Health Service Agents Registry Keys Access Medium KQL

Bert-JanP/Hunting-Queries-Detection-Rules

2 rules
Detection Severity Format
'File From Host Collected via Portal or Live Response Undefined KQL
MITRE ATT&CK Mapping Undefined KQL

elastic/protections-artifacts

2 rules
Detection Severity Format
Sensitive File Access via Rsync Undefined Elastic TOML
Sensitive File Copy via Ditto Undefined Elastic TOML

Wazuh Core Ruleset

1 rule
Detection Severity Format
Windows Security error event Low Wazuh XML

falcosecurity/rules

1 rule
Detection Severity Format
Read ssh information High Falco YAML

Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.