MITRE ATT&CK Technique
T1005Data from Local System
- First Reported
- Jul 1, 2026
- Latest Reported
- Sep 17, 2026
Official Description
Adversaries may search local system sources, such as file systems, configuration files, local databases, virtual machine files, or process memory, to find files of interest and sensitive data prior to Exfiltration.
Adversaries may do this using a [Command and Scripting Interpreter](https://attack.mitre.org/techniques/T1059), such as [cmd](https://attack.mitre.org/software/S0106) as well as a [Network Device CLI](https://attack.mitre.org/techniques/T1059/008), which have functionality to interact with the file system to gather information.(Citation: show_run_config_cmd_cisco) Adversaries may also use [Automated Collection](https://attack.mitre.org/techniques/T1119) on the local system.
Adversaries may do this using a [Command and Scripting Interpreter](https://attack.mitre.org/techniques/T1059), such as [cmd](https://attack.mitre.org/software/S0106) as well as a [Network Device CLI](https://attack.mitre.org/techniques/T1059/008), which have functionality to interact with the file system to gather information.(Citation: show_run_config_cmd_cisco) Adversaries may also use [Automated Collection](https://attack.mitre.org/techniques/T1119) on the local system.
- Tactics
- Collection
- Platforms
- ESXi, Linux, macOS, Network Devices, Windows
- MITRE Version
- 1.8
- Last Modified
- May 12, 2026
Reported Context (3)
- SparroWocky can read files from mapped storage and send their contents to its C&C server. ESET details FamousSparrow’s SparroWocky backdoor targeting Latin American governments
- C2 commands can read small local files and prepare larger files for exfiltration. Analysis of a Low-Detection Linux Implant With Hands-On Intrusion Capabilities
- The __dd__ command reads files from the device for exfiltration. Backdoor Targets Linux-Based iKuai Routers
Malware (2)
Threat Actors (3)
MITRE ATT&CK (43)
Vendors (2)
Products (4)
Tools (3)
Industries (4)
Countries (9)
Note: Related entities, including threat actors, malware, CVEs, MITRE ATT&CK techniques, vendors, products, tools, countries, and industries, are shown when they appear in the same reporting. Their presence does not necessarily mean they were targeted, compromised, vulnerable, responsible for the activity, or directly involved in the incident.