kevmap

Techniques › T1213

T1213 Data from Information Repositories

collection — Linux, Windows, macOS, SaaS, IaaS, Office Suite · attack.mitre.org · JSON

1
MITRE detection strategy
4
analytics
7
Sigma rules tagged attack.t1213
2
KEV CVEs mapped here
<p>Adversaries may leverage information repositories to mine valuable information. Information repositories are tools that allow for storage of information, typically to facilitate collaboration or information sharing between users, and can store a wide variety of data that may aid adversaries in further objectives, such as Credential Access, Lateral Movement, or Defense Evasion, or direct access to the target information. Adversaries may also abuse external sharing features to share sensitive documents with recipients outside of the organization (i.e., Transfer Data to Cloud Account).</p><p>The following is a brief list of example information that may hold potential value to an adversary and may also be found on an information repository:</p>
    <li>Policies, procedures, and standards</li><li>Physical / logical network diagrams</li><li>System architecture diagrams</li><li>Technical system documentation</li><li>Testing / development credentials (i.e., Unsecured Credentials) </li><li>Work / project schedules</li><li>Source code snippets</li><li>Links to network shares and other internal resources</li><li>Contact or other sensitive information about business partners and customers, including personally identifiable information (PII) </li>
<p>Information stored in a repository may vary based on the specific instance or environment. Specific common information repositories include the following:</p>
    <li>Storage services such as IaaS databases, enterprise databases, and more specialized platforms such as customer relationship management (CRM) databases </li><li>Collaboration platforms such as SharePoint, Confluence, and code repositories</li><li>Messaging platforms such as Slack and Microsoft Teams </li>
<p>In some cases, information repositories have been improperly secured, typically by unintentionally allowing for overly-broad access by all users or even public access to unauthenticated users. This is particularly common with cloud-native or cloud-hosted services, such as AWS Relational Database Service (RDS), Redis, or ElasticSearch.</p>

KEV CVEs mapped to this technique · CTID Mappings Explorer

CVEVendor / productMapping typeStateAdded
CVE-2023-35078Ivanti Endpoint Manager Mobile (EPMM) primary impact Mapped2023-07-25
CVE-2022-24086Adobe Commerce and Magento Open Source secondary impact Mapped2022-02-15

Detection strategy · ATT&CK Enterprise v19.2

Sigma rules · SigmaHQ da9bb07d64, tag attack.t1213

Author: Security Onion Solutions · 2024-03-08 · logsource: product=opencanary category=application · 3ec9a16d-0b4f-4967-9542-ebf38ceac7dd
Detects instances where an MSSQL service on an OpenCanary node has had a login attempt using SQLAuth.
Techniques: T1003T1213
Author: Security Onion Solutions · 2024-03-08 · logsource: product=opencanary category=application · 4fe17521-aef3-4e6a-9d6b-4a7c8de155a8
Detects instances where a GIT service on an OpenCanary node has had Git Clone request.
Techniques: T1213
Author: Muhammad Faisal (@faisalusuf) · 2024-02-25 · logsource: product=bitbucket service=audit · 5259cbf2-0a75-48bf-b57a-c54d6fabaef3
Detects user data export activity.
Author: Security Onion Solutions · 2024-03-08 · logsource: product=opencanary category=application · 547dfc53-ebf6-4afe-8d2e-793d9574975d
Detects instances where a REDIS service on an OpenCanary node has had an action command attempted.
Techniques: T1003T1213
Author: Security Onion Solutions · 2024-03-08 · logsource: product=opencanary category=application · 6e78f90f-0043-4a01-ac41-f97681613a66
Detects instances where an MSSQL service on an OpenCanary node has had a login attempt using Windows Authentication.
Techniques: T1003T1213
Author: Muhammad Faisal (@faisalusuf) · 2024-02-25 · logsource: product=bitbucket service=audit · 87cc6698-3e07-4ba2-9b43-a85a73e151e2
Detects user permission data export attempt.
Author: Security Onion Solutions · 2024-03-08 · logsource: product=opencanary category=application · e7d79a1b-25ed-4956-bd56-bd344fa8fd06
Detects instances where a MySQL service on an OpenCanary node has had a login attempt.
Techniques: T1003T1213

Sub-techniques

IDNameSigma rulesKEV CVEs
T1213.001Confluence00
T1213.002Sharepoint00
T1213.003Code Repositories50
T1213.004Customer Relationship Management Software00
T1213.005Messaging Applications00
T1213.006Databases00