{"id":"T1213.001","name":"Confluence","url":"https://attack.mitre.org/techniques/T1213/001","tactics":["collection"],"platforms":["SaaS"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0358","stix_id":"x-mitre-detection-strategy--3d515fbc-0ebf-4a99-b191-b6ee604acb1f","name":"Programmatic and Excessive Access to Confluence Documentation","url":"https://attack.mitre.org/detectionstrategies/DET0358","analytics":[{"id":"AN1019","stix_id":"x-mitre-analytic--62f43db8-4701-49b9-bb0e-a8fde37e5d07","name":"Analytic 1019","description":"Detection of excessive or programmatic access to Confluence spaces or pages, particularly by privileged users, through a combination of access logs, API usage, and identity context. Correlates logon sessions, user roles, and abnormal document viewing or export behavior. Identifies burst access patterns and tools/scripts abusing the Confluence API for mass enumeration or data scraping.","url":"https://attack.mitre.org/detectionstrategies/DET0358#AN1019","platforms":["SaaS"],"log_source_references":[{"name":"saas:confluence","channel":"access.content","data_component":"DC0038","data_component_name":"Application Log Content","log_source_slug":"saas-confluence"},{"name":"saas:confluence","channel":"logon","data_component":"DC0067","data_component_name":"Logon Session Creation","log_source_slug":"saas-confluence"},{"name":"saas:confluence","channel":"REST API access from non-browser agents","data_component":"DC0085","data_component_name":"Network Traffic Content","log_source_slug":"saas-confluence"}],"mutable_elements":[{"field":"TimeWindow","description":"Defines the time span (e.g., 5m, 1h) in which excessive access behavior becomes suspicious."},{"field":"UserContext","description":"Privileged user roles (e.g., domain admins) should be excluded or flagged if found accessing documentation repositories."},{"field":"AccessThreshold","description":"The number of pages viewed or exported by a single user before triggering detection logic."},{"field":"AgentFilter","description":"User agent strings that may indicate scripted, automated, or non-interactive access methods."}],"live":true,"detection_strategies":["DET0358"],"techniques":["T1213.001"]}],"live":true,"version":"1.0","techniques":["T1213.001"]}],"sigma_rules":[],"kev_cves":[],"_built":"2026-08-23 05:47 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}