Data from Local System T1005

Tactic: Collection

Adversaries may search local system sources, such as file systems, configuration files, local databases, virtual machine files, or process memory, to find files of interest and sensitive data prior to Exfiltration.

Events covered

20 catalog events are tagged with this technique by at least one rule.

Authoring guide

These 77 rules share fields, values, and exclusions.

Fields filtered most (87 distinct)

These fields appear most often in rule filters.

FieldRulesHowSample values
event.type27eq 24, in 3start, process_started, change
process_name27eq 16, in 13awk, cat, 7z, wget, bash
EventType25eq 17, in 8exec, open, exec_event, ProcessRollup2, executed
host.os.type25eq 25
CommandLine22contains 12, wildcard 6, regex_match 5, eq 1, match 1(?i)(((^|\s+)copy|(xcopy|robocopy)(\.exe)?"?)\s+), gitleaks, trufflehog, -s localhost , (?i)(Copy\-Item|(^|\s)copy|xcopy(\.exe"?)?|[^\-]cp|[^\-]c...
process.args22eq 8, in 8, starts_with 5, is_not_null 4, contains 3, wildcard 3, ends_with 1/bin/awk, /bin/cat, --bytes, -c, -i
Image12ends_with 10, eq 1, is_not_null 1\sqlcmd.exe, \sqlite.exe, \sqlite3.exe, /curl, /gitleaks
EventID11eq 10, in 14656, 4663, 1, 11, 18
event.category7eq 7process, file
TargetFilename5contains 2, in 2, ends_with 1, wildcard 1/library/fonts/*, /library/graphics/*, /library/webserver/*, /run/secrets/kubernetes.io/serviceaccount/ca.crt, /run/secrets/kubernetes.io/serviceaccount/namespace
sourcetype5eq 3, in 2cisco:asa, vmw-syslog, vmware:esxlog*, log4j
Esql.dest_host4is_not_null 4
Esql.destination_host_count4lt 43
Esql.host_key4is_not_null 4
Esql.verdict4in 4suspicious, tp

Top indicator values (672 distinct)

These values appear most often in rule predicates.

FieldKindValueRules (here)Corpus reach
event.typeeq
start
241078
EventTypeeq
exec
11576
EventTypeeq
open
652
EventTypein
exec
6201
EventTypein
exec_event
6149
EventTypein
start
5163
EventTypein
ProcessRollup2
4117
EventTypein
executed
498
EventTypein
process_started
483
event.categoryeq
process
6142
event.categoryeq
file
343
process_namein
cat
527
process_namein
awk
421
process_namein
sed
413
Esql.destination_host_countlt
3
44
Esql.verdictin
suspicious
44
Esql.verdictin
tp
44
container.idwildcard
*
426
Computereq
adfs_servers
35
Imageends_with
\sqlcmd.exe
35
event.typein
process_started
339
event.typein
start
341
process.argsin
/bin/awk
36
process.argsin
/bin/cat
35
process.argsin
/bin/sed
35
process.argsin
/usr/bin/awk
36
process.argsin
/usr/bin/cat
35
process.argsin
/usr/bin/sed
35
process.argsin
/usr/local/bin/awk
36
process.argsin
/usr/local/bin/cat
35

Exclusions (162 distinct)

These values appear most often in top-level exclusions.

FieldKindValueRules excluding
Esql.dest_hostin
0.0.0.0
4
Esql.dest_hostin
127.0.0.1
4
Esql.dest_hostin
168.63.129.16
4
Esql.dest_hostin
169.254.169.254
4
Esql.dest_hostin
::1
4
Esql.dest_hostin
acs-mirror.azureedge.net
4
Esql.dest_hostin
api.github.com
4
Esql.dest_hostin
artifacts.elastic.co
4
Esql.dest_hostin
download.elastic.co
4
Esql.dest_hostin
localhost
4
Esql.dest_hostin
login.microsoftonline.com
4
Esql.dest_hostin
management.azure.com
4
Esql.dest_hostin
mcr.microsoft.com
4
Esql.dest_hostin
packages.aks.azure.com
4
Esql.dest_hostin
packages.microsoft.com
4

Rules under this technique

These vendors publish rules tagged with this technique.

Platform (all)
Domain (all)

Sigma 14 rules

Elastic 38 rules

Splunk 11 rules

Kusto 10 rules

YARA-L 2 rules

Panther 2 rules