LiveActive security incident?Get immediate response
MITRE ATT&CK® Technique

T1005: Data from Local System

Adversaries may search local system sources, such as file systems, configuration files, local databases, virtual machine files, or process memory, to find files of interest and sensitive data prior to Exfiltration.

Adversaries may do this using a Command and Scripting Interpreter, such as cmd as well as a Network Device CLI, which have functionality to interact with the file system to gather information.Citationshow_run_config_cmd_cisco Adversaries may also use Automated Collection on the local system.

EnterpriseT1005TechniqueObject v1.8Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceHigh

Data from Local System is the point in an intrusion where an adversary looks across a compromised host or device for valuable local content before exfiltration. For leaders, the business issue is not just “file access”; it is whether sensitive documents, configuration data, local databases, virtual machine files, process memory, or network device configurations can be found, staged, and removed before the organization notices.

Executive priority

Prioritize this technique where regulated data, intellectual property, operational technology support data, executive files, source code, financial records, or network device configurations reside on endpoints, servers, ESXi hosts, macOS/Linux/Windows systems, or network devices. It is especially relevant to incident response scoping and audit evidence: teams should be able to show what sensitive data exists locally, who or what accessed it, and whether controls such as Data Loss Prevention are monitoring movement from those systems.

Technical view

ATT&CK places T1005 in the Collection tactic and describes local searches across file systems, configuration files, local databases, VM files, and process memory, potentially using command and scripting interpreters, cmd, network device CLI, or automated collection. SOC and IR teams should validate visibility for local file discovery and access patterns across the listed platforms: ESXi, Linux, macOS, Network Devices, and Windows. Because official detection text is not provided, detection engineering should reference the related DET0380 strategy and build environment-specific analytics around unusual access to sensitive local data sources, especially when preceded by interpreter use or followed by staging or exfiltration-related behavior.

Likely telemetry

  • Endpoint process execution telemetry for command interpreters and scripting activity
  • File access, file enumeration, and sensitive directory access logs where available
  • Operating system audit logs from Windows, Linux, and macOS hosts
  • Network device command/accounting logs, including configuration-viewing activity such as running configuration access
  • ESXi and virtualization platform logs for access to virtual machine files

Detection direction

  • Confirm whether logging captures both the access mechanism and the data target; process telemetry without file/object context may miss the business impact.
  • Tune detections for unusual local collection behavior by account, host role, time, volume, and data sensitivity rather than simple file reads alone, which can be noisy.
  • Correlate local collection with related behaviors named in the ATT&CK description, including command and scripting interpreter use and automated collection.
  • Include network devices in coverage reviews; configuration file access through device CLI can be high value but is often outside endpoint-centric monitoring.
  • Use the related DET0380 detection strategy as a starting point, but require local validation because the ATT&CK object does not provide official detection logic.

Mitigation priorities

  • Start with data classification and location mapping so defenders know which local stores require monitoring and protection.
  • Apply Data Loss Prevention controls consistent with related mitigation M1057 to identify, categorize, monitor, and control sensitive data movement across endpoint, network, and cloud-adjacent paths.
  • Reduce unnecessary local copies of sensitive data and restrict access to local databases, configuration files, VM files, and administrative directories based on role.
  • Harden and monitor administrative access to network devices and virtualization infrastructure because local configuration and VM data may be business-critical.
  • Ensure incident response playbooks include collection-scope analysis, not only malware removal, so legal, compliance, and business owners can make informed decisions.
Additional notes and limits

Relationship context shows this technique has been used across many ATT&CK campaigns and groups, including espionage, ransomware, supply chain, and infrastructure-focused activity. That breadth supports treating T1005 as a common collection behavior, but it does not by itself prove current exposure or active targeting of any specific organization.

The supplied ATT&CK object provides no official detection text and no procedure-level details in this prompt. Any detection or control assessment must be validated against local data locations, logging coverage, endpoint and device platforms, retention, and DLP configuration.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

Data from Local System

Adversaries may search local system sources, such as file systems, configuration files, local databases, virtual machine files, or process memory, to find files of interest and sensitive data prior to Exfiltration.

Adversaries may do this using a Command and Scripting Interpreter, such as cmd as well as a Network Device CLI, which have functionality to interact with the file system to gather information.Citationshow_run_config_cmd_cisco Adversaries may also use Automated Collection on the local system.

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

Relationship explorer

All related ATT&CK context

No relationships are available in the current normalized data for this object.

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.1
Object version
1.8
Created
Modified
Raw hash
4c85bbbbab006e60...
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.