Adversaries may target and collect data from local system sources, such as file systems, configuration files, or local databases. This can include sensitive data such as specifications, schematics, or diagrams of control system layouts, devices, and processes. Adversaries may do this using [Command-Line Interface](https://attack.mitre.org/techniques/T0807) or [Scripting](https://attack.mitre.org/techniques/T0853) techniques to interact with the file system to gather information. Adversaries may also use [Automated Collection](https://attack.mitre.org/techniques/T0802) on the local system.

Linked Issues

Issuelinks
Linktyp Issue
is related to Techniques
is related to Firewall
is related to Control Server
is related to Switch
is related to Data Historian
is related to Human-Machine Interface (HMI)
is related to Application Server
is related to Workstation
is related to Jump Host
is blocked by Encrypt Sensitive Information
is blocked by Data Loss Prevention
is blocked by Restrict File and Directory Permissions
is blocked by User Training
is blocked by Detection of Data from Local System
Impressum Deutsch Englisch