Techniques › T1213 › AN1160
AN1160 Analytic 1160
Windows · attack.mitre.org · ATT&CK Enterprise v19.2
<p>Programmatic or excessive access to file shares, SharePoint, or database repositories by users not typically interacting with them. This includes abnormal access by privileged accounts, enumeration of large numbers of files, or downloads of sensitive content in bursts.</p>
- Detects
- T1213 Data from Information Repositories
- Part of
- DET0413 Abuse of Information Repositories for Data Collection
Log sources and channels
Exactly as MITRE states them in x_mitre_log_source_references. Where a channel is vague, it is vague in the source; kevmap does not tidy it.
| Log source | Channel | Data component |
|---|---|---|
| WinEventLog:Security | EventCode=5145 | DC0102 Network Share Access |
| m365:unified | Accessed SharePoint files or pages | DC0025 Cloud Storage Access |
Mutable elements
Parameters MITRE marks as environment-specific. These are the knobs you are expected to tune; they are why an analytic is not a rule.
| Field | Description |
|---|---|
UserContext | Privileged users may be excluded if they routinely perform admin actions on SharePoint or file shares. |
AccessVolumeThreshold | The number of files accessed or pages retrieved in a short window to flag as abnormal. |
TimeWindow | The time range (e.g., 5 minutes, 1 hour) in which burst access patterns are considered anomalous. |
KEV CVEs whose mapped technique this analytic detects
| CVE | Vendor / product | State |
|---|---|---|
| CVE-2022-24086 | Adobe Commerce and Magento Open Source | Mapped |
| CVE-2023-35078 | Ivanti Endpoint Manager Mobile (EPMM) | Mapped |