MITRE ATT&CK technique
Data from Local System detection rulesT1005
Data from Local System (T1005) is a MITRE ATT&CK technique in the Collection tactic. This page lists the 14 community-maintained Sigma detection rules in the library mapped to T1005 and its sub-techniques. Each rule includes its detection logic, log source, false positives and original YAML. These rules mainly target windows, linux, opencanary.
Top products
Tactic
OpenCanary - SMB File Open Request
highDetects instances where an SMB service on an OpenCanary node has had a file open request.
opencanary · application
Potential Conti Ransomware Database Dumping Activity Via SQLCmd
highDetects a command used by conti to dump database
windows · process_creation
Script Interpreter Spawning Credential Scanner - Linux
highDetects a script interpreter process (like node.js or bun) spawning a known credential scanning tool (e.g., trufflehog, gitleaks). This behavior is indicative of an attempt to find and steal secrets, as seen in the "Shai-Hulud: The Second Coming" campaign.
linux · process_creation
Script Interpreter Spawning Credential Scanner - Windows
highDetects a script interpreter process (like node.js or bun) spawning a known credential scanning tool (e.g., trufflehog, gitleaks). This behavior is indicative of an attempt to find and steal secrets, as seen in the "Shai-Hulud: The Second Coming" campaign.
windows · process_creation
Shai-Hulud NPM Package Malicious Exfiltration via Curl
highDetects potential Shai Hulud NPM package attack attempting to exfiltrate data via curl to external webhook sites.
linux · process_creation
SQLite Chromium Profile Data DB Access
highDetect usage of the "sqlite" binary to query databases in Chromium-based browsers for potential data stealing.
windows · process_creation
SQLite Firefox Profile Data DB Access
highDetect usage of the "sqlite" binary to query databases in Firefox and other Gecko-based browsers for potential data stealing.
windows · process_creation
VeeamBackup Database Credentials Dump Via Sqlcmd.EXE
highDetects dump of credentials in VeeamBackup dbo
windows · process_creation
ADFS Database Named Pipe Connection By Uncommon Tool
mediumDetects suspicious local connections via a named pipe to the AD FS configuration database (Windows Internal Database). Used to access information such as the AD FS configuration settings which contains sensitive information used to sign SAML tokens.
windows · pipe_created
Crash Dump Created By Operating System
mediumDetects "BugCheck" errors indicating the system rebooted due to a crash, capturing the bugcheck code, dump file path, and report ID.
windows
Esentutl Steals Browser Information
mediumOne way Qbot steals sensitive information is by extracting browser data from Internet Explorer and Microsoft Edge by using the built-in utility esentutl.exe
windows · process_creation
Veeam Backup Database Suspicious Query
mediumDetects potentially suspicious SQL queries using SQLCmd targeting the Veeam backup databases in order to steal information.
windows · process_creation
AWS EC2 VM Export Failure
lowAn attempt to export an AWS EC2 instance has been detected. A VM Export might indicate an attempt to extract information from an instance.
aws
Cisco Collect Data
lowCollect pertinent data from the configuration files
cisco