Cross-source coverage

T1213 / ATT&CK

Data from Information Repositories

93 rules · 92 families across 8 sources.

From MITRE ATT&CK 19.2

Adversaries may leverage information repositories to mine valuable information. Information repositories are tools that allow for storage of information, typically to facilitate collaboration or information sharing between users, and can store a wide variety of data that may aid adversaries in further objectives, such as Credential Access, Lateral Movement, or Defense Evasion, or direct access to the target information. Adversaries may also abuse external sharing features to share sensitive documents with recipients outside of the organization (i.e., Transfer Data to Cloud Account).

The following is a brief list of example information that may hold potential value to an adversary and may also be found on an information repository:

  • Policies, procedures, and standards
  • Physical / logical network diagrams
  • System architecture diagrams
  • Technical system documentation
  • Testing / development credentials (i.e., Unsecured Credentials)
  • Work / project schedules
  • Source code snippets
  • Links to network shares and other internal resources
  • Contact or other sensitive information about business partners and customers, including personally identifiable information (PII)

Information stored in a repository may vary based on the specific instance or environment. Specific common information repositories include the following:

  • Storage services such as IaaS databases, enterprise databases, and more specialized platforms such as customer relationship management (CRM) databases
  • Collaboration platforms such as SharePoint, Confluence, and code repositories
  • Messaging platforms such as Slack and Microsoft Teams

In some cases, information repositories have been improperly secured, typically by unintentionally allowing for overly-broad access by all users or even public access to unauthenticated users. This is particularly common with cloud-native or cloud-hosted services, such as AWS Relational Database Service (RDS), Redis, or ElasticSearch.

Tactics
Collection
Platforms
Linux · Windows · macOS · SaaS · IaaS · Office Suite
Telemetry
WinEventLog:Securitym365:unifiedauditd:SYSCALLlinux:Sysmonsaas:confluencesaas:slackmacos:unifiedlogmacos:osquery

How MITRE says to detect it DET0413

Abuse of Information Repositories for Data Collection

Windows Analytic 1160

Programmatic or excessive access to file shares, SharePoint, or database repositories by users not typically interacting with them. This includes abnormal access by privileged accounts, enumeration of large numbers of files, or downloads of sensitive content in bursts.

  • WinEventLog:Security EventCode=5145
  • m365:unified Accessed SharePoint files or pages

Linux Analytic 1161

Command-line tools (e.g., curl, rsync, wget, or custom Python scripts) used to scrape documentation systems or internal REST APIs. Unusual access patterns to knowledge base folders or shared team drives.

  • auditd:SYSCALL execve of curl, rsync, wget with internal knowledge base or IPs
  • linux:Sysmon EventCode=3, 22

SaaS Analytic 1162

Abuse of SaaS platforms such as Confluence, GitHub, SharePoint Online, or Slack to access excessive internal documentation or export source code/data. Includes use of tokens or browser automation from unapproved IPs.

  • saas:confluence access.content
  • saas:slack Exported file or accessed admin API

macOS Analytic 1163

Access of mounted cloud shares or document repositories via browser, terminal, or Finder by users not typically interacting with those resources. Includes script-based enumeration or mass download.

  • macos:unifiedlog access to /Volumes/SharePoint or network mount
  • macos:osquery curl, python scripts, rsync with internal share URLs

Sub-techniques with coverage

Counted in the 93 above — a rule tagged a sub-technique covers this technique too.


socfortress/Wazuh-Rules

36 rules
Detection Severity Format
operation. · office_365.Operation = DlpRuleMatch High Wazuh XML
operation. · office_365.Operation = BindMonikersToDatasources Low Wazuh XML
operation. · office_365.Operation = CreateDataset Low Wazuh XML
operation. · office_365.Operation = CreateReport Low Wazuh XML
operation. · office_365.Operation = DeleteDatasetRows Low Wazuh XML
operation. · office_365.Operation = DLPRuleUndo Low Wazuh XML
operation. · office_365.Operation = DownloadReport Low Wazuh XML
operation. · office_365.Operation = EditDataset Low Wazuh XML
operation. · office_365.Operation = EditFlow Low Wazuh XML
operation. · office_365.Operation = EditForm Low Wazuh XML

+ 26 more from socfortress/Wazuh-Rules → showing the 10 highest-severity

elastic/detection-rules

18 rules
Detection Severity Format
AWS DynamoDB Table Exported to S3 High Elastic TOML
AWS RDS Snapshot Export High Elastic TOML
M365 SharePoint/OneDrive File Access via PowerShell High Elastic TOML
Access to a Sensitive LDAP Attribute Medium Elastic TOML
AWS Secrets Manager Rapid Secrets Retrieval Medium Elastic TOML
Azure Key Vault Excessive Secret or Key Retrieved Medium Elastic TOML
Entra ID Sharepoint or OneDrive Accessed by Unusual Client Medium Elastic TOML
First Time Seen NFS AUTH_SYS Root UID Access Medium Elastic TOML
GitHub Exfiltration via High Number of Repository Clones by User Medium Elastic TOML
Kubernetes Secret or ConfigMap Access via Azure Arc Proxy Medium Elastic TOML

+ 8 more from elastic/detection-rules → showing the 10 highest-severity

SigmaHQ/sigma

12 rules
Detection Severity Format
Bitbucket Unauthorized Full Data Export Triggered Critical Sigma
Bitbucket Full Data Export Triggered High Sigma
OpenCanary - GIT Clone Request High Sigma
OpenCanary - MSSQL Login Attempt Via SQLAuth High Sigma
OpenCanary - MSSQL Login Attempt Via Windows Authentication High Sigma
OpenCanary - MySQL Login Attempt High Sigma
OpenCanary - REDIS Action Command Attempt High Sigma
Bitbucket User Details Export Attempt Detected Medium Sigma
Bitbucket User Permissions Export Attempt Medium Sigma
Github Delete Action Invoked Medium Sigma

+ 2 more from SigmaHQ/sigma → showing the 10 highest-severity

panther-labs/panther-analysis

10 rules · 9 families
Detection Severity Format
Snowflake Data Exfiltration 2 variants Critical Panther Python
Snowflake Data Exfiltration 2 variants Critical Panther Python
External GSuite File Share High Panther Python
Okta SWA Bulk Access, New Source, and Credential Extraction - Behavioral High Panther Python
Zendesk Credit Card Redaction Off High Panther Python
AppOmni Alert Passthrough Medium Panther Python
Databricks TruffleHog Scan Detected Medium Panther Python
GSuite Document External Ownership Transfer Low Panther Python
GSuite External Drive Document Low Panther Python
GSuite Overly Visible Drive Document Informational Panther Python

Azure/Azure-Sentinel

9 rules
Detection Severity Format
Users searching for VIP user activity Low KQL
Cross workspace query anomolies Undefined KQL
GitHub Repo Clone - Time Series Anomly Undefined KQL
GitHub Repo switched from private to public Undefined KQL
New client running queries Undefined KQL
New ServicePrincipal running queries Undefined KQL
New users calling sensitive Watchlist Undefined KQL
New users running queries Undefined KQL
Query looking for secrets Undefined KQL

Wazuh Core Ruleset

4 rules
Detection Severity Format
Office 365: Suspicious download activity by user · rule 91724 High Wazuh XML
Office 365: Data loss protection (DLP) events in SharePoint and OneDrive for Business. Low Wazuh XML
Office 365: Events related to DLP classification in SharePoint. Low Wazuh XML
Office 365: SharePoint sharing events. Low Wazuh XML

chronicle/detection-rules

3 rules
Detection Severity Format
github_access_granted_to_personal_access_token_followed_by_high_number_of_cloned_non_public_repositories High YARA-L
github_high_number_of_non_public_github_repositories_cloned High YARA-L
github_high_number_of_non_public_github_repositories_downloaded High YARA-L

splunk/security_content

1 rule
Detection Severity Format
O365 SharePoint Suspicious Search Behavior Undefined SPL

Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.