{"id":"T1213","name":"Data from Information Repositories","url":"https://attack.mitre.org/techniques/T1213","tactics":["collection"],"platforms":["Linux","Windows","macOS","SaaS","IaaS","Office Suite"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0413","stix_id":"x-mitre-detection-strategy--48e8d8b1-0117-48bd-a32d-f4e43b665bf3","name":"Abuse of Information Repositories for Data Collection","url":"https://attack.mitre.org/detectionstrategies/DET0413","analytics":[{"id":"AN1160","stix_id":"x-mitre-analytic--7dce56f3-43db-4787-ae13-bd2ce6851088","name":"Analytic 1160","description":"Programmatic or excessive access to file shares, SharePoint, or database repositories by users not typically interacting with them. This includes abnormal access by privileged accounts, enumeration of large numbers of files, or downloads of sensitive content in bursts.","url":"https://attack.mitre.org/detectionstrategies/DET0413#AN1160","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Security","channel":"EventCode=5145","data_component":"DC0102","data_component_name":"Network Share Access","log_source_slug":"wineventlog-security"},{"name":"m365:unified","channel":"Accessed SharePoint files or pages","data_component":"DC0025","data_component_name":"Cloud Storage Access","log_source_slug":"m365-unified"}],"mutable_elements":[{"field":"UserContext","description":"Privileged users may be excluded if they routinely perform admin actions on SharePoint or file shares."},{"field":"AccessVolumeThreshold","description":"The number of files accessed or pages retrieved in a short window to flag as abnormal."},{"field":"TimeWindow","description":"The time range (e.g., 5 minutes, 1 hour) in which burst access patterns are considered anomalous."}],"live":true,"detection_strategies":["DET0413"],"techniques":["T1213"]},{"id":"AN1161","stix_id":"x-mitre-analytic--59faf79f-831d-436b-9ce3-e5c1d338da6c","name":"Analytic 1161","description":"Command-line tools (e.g., curl, rsync, wget, or custom Python scripts) used to scrape documentation systems or internal REST APIs. Unusual access patterns to knowledge base folders or shared team drives.","url":"https://attack.mitre.org/detectionstrategies/DET0413#AN1161","platforms":["Linux"],"log_source_references":[{"name":"auditd:SYSCALL","channel":"execve of curl, rsync, wget with internal knowledge base or IPs","data_component":"DC0064","data_component_name":"Command Execution","log_source_slug":"auditd-syscall"},{"name":"linux:Sysmon","channel":"EventCode=3, 22","data_component":"DC0082","data_component_name":"Network Connection Creation","log_source_slug":"linux-sysmon"}],"mutable_elements":[{"field":"CommandRegex","description":"Regex matching internal doc servers, knowledge base paths, or IP patterns."},{"field":"TimeWindow","description":"Burst access of repositories over a short time window."}],"live":true,"detection_strategies":["DET0413"],"techniques":["T1213"]},{"id":"AN1162","stix_id":"x-mitre-analytic--3655f892-ed0d-4b76-9173-ecb7eebacd8a","name":"Analytic 1162","description":"Abuse of SaaS platforms such as Confluence, GitHub, SharePoint Online, or Slack to access excessive internal documentation or export source code/data. Includes use of tokens or browser automation from unapproved IPs.","url":"https://attack.mitre.org/detectionstrategies/DET0413#AN1162","platforms":["SaaS"],"log_source_references":[{"name":"saas:confluence","channel":"access.content","data_component":"DC0038","data_component_name":"Application Log Content","log_source_slug":"saas-confluence"},{"name":"saas:slack","channel":"Exported file or accessed admin API","data_component":"DC0069","data_component_name":"Cloud Service Modification","log_source_slug":"saas-slack"}],"mutable_elements":[{"field":"APIUsageThreshold","description":"Number of API calls or files accessed before triggering detection."},{"field":"KnownSafeIPs","description":"Whitelist of internal IPs/users that may be excluded from detection."}],"live":true,"detection_strategies":["DET0413"],"techniques":["T1213"]},{"id":"AN1163","stix_id":"x-mitre-analytic--eac7b88d-0ee2-4fbf-9e0b-ea73c376ccb3","name":"Analytic 1163","description":"Access of mounted cloud shares or document repositories via browser, terminal, or Finder by users not typically interacting with those resources. Includes script-based enumeration or mass download.","url":"https://attack.mitre.org/detectionstrategies/DET0413#AN1163","platforms":["macOS"],"log_source_references":[{"name":"macos:unifiedlog","channel":"access to /Volumes/SharePoint or network mount","data_component":"DC0055","data_component_name":"File Access","log_source_slug":"macos-unifiedlog"},{"name":"macos:osquery","channel":"curl, python scripts, rsync with internal share URLs","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"macos-osquery"}],"mutable_elements":[{"field":"AccessedMountPath","description":"Paths to sensitive volumes may differ based on org setup."},{"field":"UserGroup","description":"Expected user groups that typically access shared data."}],"live":true,"detection_strategies":["DET0413"],"techniques":["T1213"]}],"live":true,"version":"1.0","techniques":["T1213"]}],"sigma_rules":[{"id":"3ec9a16d-0b4f-4967-9542-ebf38ceac7dd","title":"OpenCanary - MSSQL Login Attempt Via SQLAuth","author":"Security Onion Solutions","status":"test","level":"high","date":"2024-03-08","modified":null,"description":"Detects instances where an MSSQL service on an OpenCanary node has had a login attempt using SQLAuth.\n","references":["https://opencanary.readthedocs.io/en/latest/starting/configuration.html#services-configuration","https://github.com/thinkst/opencanary/blob/a0896adfcaf0328cfd5829fe10d2878c7445138e/opencanary/logger.py#L52"],"logsource":{"product":"opencanary","category":"application"},"tags":["attack.credential-access","attack.collection","attack.t1003","attack.t1213"],"path":"rules/application/opencanary/opencanary_mssql_login_sqlauth.yml","techniques":["T1003","T1213"],"cves":[]},{"id":"4fe17521-aef3-4e6a-9d6b-4a7c8de155a8","title":"OpenCanary - GIT Clone Request","author":"Security Onion Solutions","status":"test","level":"high","date":"2024-03-08","modified":null,"description":"Detects instances where a GIT service on an OpenCanary node has had Git Clone request.","references":["https://opencanary.readthedocs.io/en/latest/starting/configuration.html#services-configuration","https://github.com/thinkst/opencanary/blob/a0896adfcaf0328cfd5829fe10d2878c7445138e/opencanary/logger.py#L52"],"logsource":{"product":"opencanary","category":"application"},"tags":["attack.collection","attack.t1213"],"path":"rules/application/opencanary/opencanary_git_clone_request.yml","techniques":["T1213"],"cves":[]},{"id":"5259cbf2-0a75-48bf-b57a-c54d6fabaef3","title":"Bitbucket User Details Export Attempt Detected","author":"Muhammad Faisal (@faisalusuf)","status":"test","level":"medium","date":"2024-02-25","modified":null,"description":"Detects user data export activity.","references":["https://confluence.atlassian.com/bitbucketserver/audit-log-events-776640423.html","https://support.atlassian.com/security-and-access-policies/docs/export-user-accounts"],"logsource":{"product":"bitbucket","service":"audit"},"tags":["attack.collection","attack.reconnaissance","attack.discovery","attack.t1213","attack.t1082","attack.t1591.004"],"path":"rules/application/bitbucket/audit/bitbucket_audit_user_details_export_attempt_detected.yml","techniques":["T1213","T1082","T1591.004"],"cves":[]},{"id":"547dfc53-ebf6-4afe-8d2e-793d9574975d","title":"OpenCanary - REDIS Action Command Attempt","author":"Security Onion Solutions","status":"test","level":"high","date":"2024-03-08","modified":null,"description":"Detects instances where a REDIS service on an OpenCanary node has had an action command attempted.","references":["https://opencanary.readthedocs.io/en/latest/starting/configuration.html#services-configuration","https://github.com/thinkst/opencanary/blob/a0896adfcaf0328cfd5829fe10d2878c7445138e/opencanary/logger.py#L52"],"logsource":{"product":"opencanary","category":"application"},"tags":["attack.credential-access","attack.collection","attack.t1003","attack.t1213"],"path":"rules/application/opencanary/opencanary_redis_command.yml","techniques":["T1003","T1213"],"cves":[]},{"id":"6e78f90f-0043-4a01-ac41-f97681613a66","title":"OpenCanary - MSSQL Login Attempt Via Windows Authentication","author":"Security Onion Solutions","status":"test","level":"high","date":"2024-03-08","modified":null,"description":"Detects instances where an MSSQL service on an OpenCanary node has had a login attempt using Windows Authentication.\n","references":["https://opencanary.readthedocs.io/en/latest/starting/configuration.html#services-configuration","https://github.com/thinkst/opencanary/blob/a0896adfcaf0328cfd5829fe10d2878c7445138e/opencanary/logger.py#L52"],"logsource":{"product":"opencanary","category":"application"},"tags":["attack.credential-access","attack.collection","attack.t1003","attack.t1213"],"path":"rules/application/opencanary/opencanary_mssql_login_winauth.yml","techniques":["T1003","T1213"],"cves":[]},{"id":"87cc6698-3e07-4ba2-9b43-a85a73e151e2","title":"Bitbucket User Permissions Export Attempt","author":"Muhammad Faisal (@faisalusuf)","status":"test","level":"medium","date":"2024-02-25","modified":null,"description":"Detects user permission data export attempt.","references":["https://confluence.atlassian.com/bitbucketserver/audit-log-events-776640423.html","https://confluence.atlassian.com/bitbucketserver/users-and-groups-776640439.html"],"logsource":{"product":"bitbucket","service":"audit"},"tags":["attack.reconnaissance","attack.collection","attack.discovery","attack.t1213","attack.t1082","attack.t1591.004"],"path":"rules/application/bitbucket/audit/bitbucket_audit_user_permissions_export_attempt_detected.yml","techniques":["T1213","T1082","T1591.004"],"cves":[]},{"id":"e7d79a1b-25ed-4956-bd56-bd344fa8fd06","title":"OpenCanary - MySQL Login Attempt","author":"Security Onion Solutions","status":"test","level":"high","date":"2024-03-08","modified":null,"description":"Detects instances where a MySQL service on an OpenCanary node has had a login attempt.","references":["https://opencanary.readthedocs.io/en/latest/starting/configuration.html#services-configuration","https://github.com/thinkst/opencanary/blob/a0896adfcaf0328cfd5829fe10d2878c7445138e/opencanary/logger.py#L52"],"logsource":{"product":"opencanary","category":"application"},"tags":["attack.credential-access","attack.collection","attack.t1003","attack.t1213"],"path":"rules/application/opencanary/opencanary_mysql_login_attempt.yml","techniques":["T1003","T1213"],"cves":[]}],"kev_cves":[{"cveID":"CVE-2023-35078","state":"mapped","mapping_types":["primary_impact"]},{"cveID":"CVE-2022-24086","state":"mapped","mapping_types":["secondary_impact"]}],"_built":"2026-08-23 05:47 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}