Techniques › T1213
T1213 Data from Information Repositories
collection — Linux, Windows, macOS, SaaS, IaaS, Office Suite · attack.mitre.org · JSON
1
MITRE detection strategy
4
analytics
7
Sigma rules tagged attack.t1213
2
KEV CVEs mapped here
<p>Adversaries may leverage information repositories to mine valuable information. Information repositories are tools that allow for storage of information, typically to facilitate collaboration or information sharing between users, and can store a wide variety of data that may aid adversaries in further objectives, such as Credential Access, Lateral Movement, or Defense Evasion, or direct access to the target information. Adversaries may also abuse external sharing features to share sensitive documents with recipients outside of the organization (i.e., Transfer Data to Cloud Account).</p><p>The following is a brief list of example information that may hold potential value to an adversary and may also be found on an information repository:</p>
- <li>Policies, procedures, and standards</li><li>Physical / logical network diagrams</li><li>System architecture diagrams</li><li>Technical system documentation</li><li>Testing / development credentials (i.e., Unsecured Credentials) </li><li>Work / project schedules</li><li>Source code snippets</li><li>Links to network shares and other internal resources</li><li>Contact or other sensitive information about business partners and customers, including personally identifiable information (PII) </li>
- <li>Storage services such as IaaS databases, enterprise databases, and more specialized platforms such as customer relationship management (CRM) databases </li><li>Collaboration platforms such as SharePoint, Confluence, and code repositories</li><li>Messaging platforms such as Slack and Microsoft Teams </li>
KEV CVEs mapped to this technique · CTID Mappings Explorer
| CVE | Vendor / product | Mapping type | State | Added |
|---|---|---|---|---|
| CVE-2023-35078 | Ivanti Endpoint Manager Mobile (EPMM) | primary impact | Mapped | 2023-07-25 |
| CVE-2022-24086 | Adobe Commerce and Magento Open Source | secondary impact | Mapped | 2022-02-15 |
Detection strategy · ATT&CK Enterprise v19.2
- DET0413 Abuse of Information Repositories for Data Collection v1.0
AN1160 WindowsProgrammatic or excessive access to file shares, SharePoint, or database repositories by users not typically interacting with them. This includes abnormal access by privileged accounts, enumeration of large numbers of files, or downloads of sensitive content in bursts.Tunable:
UserContextAccessVolumeThresholdTimeWindowAN1161 LinuxCommand-line tools (e.g., curl, rsync, wget, or custom Python scripts) used to scrape documentation systems or internal REST APIs. Unusual access patterns to knowledge base folders or shared team drives.auditd:SYSCALLexecve of curl, rsync, wget with internal knowledge base or IPs→ DC0064 Command ExecutionTunable:CommandRegexTimeWindowAN1162 SaaSAbuse of SaaS platforms such as Confluence, GitHub, SharePoint Online, or Slack to access excessive internal documentation or export source code/data. Includes use of tokens or browser automation from unapproved IPs.Tunable:APIUsageThresholdKnownSafeIPsAN1163 macOSAccess of mounted cloud shares or document repositories via browser, terminal, or Finder by users not typically interacting with those resources. Includes script-based enumeration or mass download.Tunable:AccessedMountPathUserGroup
Sigma rules · SigmaHQ da9bb07d64, tag attack.t1213
Author: Security Onion Solutions
· 2024-03-08 · logsource: product=opencanary category=application · 3ec9a16d-0b4f-4967-9542-ebf38ceac7dd
Detects instances where an MSSQL service on an OpenCanary node has had a login attempt using SQLAuth.
Author: Security Onion Solutions
· 2024-03-08 · logsource: product=opencanary category=application · 4fe17521-aef3-4e6a-9d6b-4a7c8de155a8
Detects instances where a GIT service on an OpenCanary node has had Git Clone request.
Author: Muhammad Faisal (@faisalusuf)
· 2024-02-25 · logsource: product=bitbucket service=audit · 5259cbf2-0a75-48bf-b57a-c54d6fabaef3
Detects user data export activity.
Author: Security Onion Solutions
· 2024-03-08 · logsource: product=opencanary category=application · 547dfc53-ebf6-4afe-8d2e-793d9574975d
Detects instances where a REDIS service on an OpenCanary node has had an action command attempted.
Author: Security Onion Solutions
· 2024-03-08 · logsource: product=opencanary category=application · 6e78f90f-0043-4a01-ac41-f97681613a66
Detects instances where an MSSQL service on an OpenCanary node has had a login attempt using Windows Authentication.
Author: Muhammad Faisal (@faisalusuf)
· 2024-02-25 · logsource: product=bitbucket service=audit · 87cc6698-3e07-4ba2-9b43-a85a73e151e2
Detects user permission data export attempt.
Author: Security Onion Solutions
· 2024-03-08 · logsource: product=opencanary category=application · e7d79a1b-25ed-4956-bd56-bd344fa8fd06
Detects instances where a MySQL service on an OpenCanary node has had a login attempt.