Data from Local System
Think of this like a burglar rummaging through a desk drawer to find important documents or keys before they leave the house. In the digital world, an attacker looks through your computer's folders and settings to find valuable information they can steal later.
This refers to the discovery phase where an adversary explores a compromised host's file system, configuration files, or local databases. The goal is to identify and stage sensitive assets—such as SSH keys, credentials, or proprietary data—to facilitate subsequent exfiltration.
A post-compromise activity wherein an adversary performs systematic discovery of local system sources, including file systems, configuration files, and local databases, to identify and aggregate sensitive data or artifacts of interest. This process, which may involve basic fingerprinting, is a prerequisite for exfiltration and often targets high-value assets such as cryptographic keys, configuration secrets, and intellectual property.