Cross-source coverage
T1213 / ATT&CK
Data from Information Repositories
From MITRE ATT&CK 19.2
Adversaries may leverage information repositories to mine valuable information. Information repositories are tools that allow for storage of information, typically to facilitate collaboration or information sharing between users, and can store a wide variety of data that may aid adversaries in further objectives, such as Credential Access, Lateral Movement, or Defense Evasion, or direct access to the target information. Adversaries may also abuse external sharing features to share sensitive documents with recipients outside of the organization (i.e., Transfer Data to Cloud Account).
The following is a brief list of example information that may hold potential value to an adversary and may also be found on an information repository:
- Policies, procedures, and standards
- Physical / logical network diagrams
- System architecture diagrams
- Technical system documentation
- Testing / development credentials (i.e., Unsecured Credentials)
- Work / project schedules
- Source code snippets
- Links to network shares and other internal resources
- Contact or other sensitive information about business partners and customers, including personally identifiable information (PII)
Information stored in a repository may vary based on the specific instance or environment. Specific common information repositories include the following:
- Storage services such as IaaS databases, enterprise databases, and more specialized platforms such as customer relationship management (CRM) databases
- Collaboration platforms such as SharePoint, Confluence, and code repositories
- Messaging platforms such as Slack and Microsoft Teams
In some cases, information repositories have been improperly secured, typically by unintentionally allowing for overly-broad access by all users or even public access to unauthenticated users. This is particularly common with cloud-native or cloud-hosted services, such as AWS Relational Database Service (RDS), Redis, or ElasticSearch.
- Tactics
- Collection
- Platforms
- Linux · Windows · macOS · SaaS · IaaS · Office Suite
- Telemetry
-
WinEventLog:Securitym365:unifiedauditd:SYSCALLlinux:Sysmonsaas:confluencesaas:slackmacos:unifiedlogmacos:osquery
How MITRE says to detect it DET0413
Abuse of Information Repositories for Data Collection
Windows Analytic 1160
Programmatic or excessive access to file shares, SharePoint, or database repositories by users not typically interacting with them. This includes abnormal access by privileged accounts, enumeration of large numbers of files, or downloads of sensitive content in bursts.
WinEventLog:SecurityEventCode=5145m365:unifiedAccessed SharePoint files or pages
Linux Analytic 1161
Command-line tools (e.g., curl, rsync, wget, or custom Python scripts) used to scrape documentation systems or internal REST APIs. Unusual access patterns to knowledge base folders or shared team drives.
auditd:SYSCALLexecve of curl, rsync, wget with internal knowledge base or IPslinux:SysmonEventCode=3, 22
SaaS Analytic 1162
Abuse of SaaS platforms such as Confluence, GitHub, SharePoint Online, or Slack to access excessive internal documentation or export source code/data. Includes use of tokens or browser automation from unapproved IPs.
saas:confluenceaccess.contentsaas:slackExported file or accessed admin API
macOS Analytic 1163
Access of mounted cloud shares or document repositories via browser, terminal, or Finder by users not typically interacting with those resources. Includes script-based enumeration or mass download.
macos:unifiedlogaccess to /Volumes/SharePoint or network mountmacos:osquerycurl, python scripts, rsync with internal share URLs
Sub-techniques with coverage
Counted in the 93 above — a rule tagged a sub-technique covers this technique too.
socfortress/Wazuh-Rules
36 rules| Detection | Severity | Format |
|---|---|---|
| operation. · office_365.Operation = DlpRuleMatch | High | Wazuh XML |
| operation. · office_365.Operation = BindMonikersToDatasources | Low | Wazuh XML |
| operation. · office_365.Operation = CreateDataset | Low | Wazuh XML |
| operation. · office_365.Operation = CreateReport | Low | Wazuh XML |
| operation. · office_365.Operation = DeleteDatasetRows | Low | Wazuh XML |
| operation. · office_365.Operation = DLPRuleUndo | Low | Wazuh XML |
| operation. · office_365.Operation = DownloadReport | Low | Wazuh XML |
| operation. · office_365.Operation = EditDataset | Low | Wazuh XML |
| operation. · office_365.Operation = EditFlow | Low | Wazuh XML |
| operation. · office_365.Operation = EditForm | Low | Wazuh XML |
+ 26 more from socfortress/Wazuh-Rules → showing the 10 highest-severity
elastic/detection-rules
18 rules| Detection | Severity | Format |
|---|---|---|
| AWS DynamoDB Table Exported to S3 | High | Elastic TOML |
| AWS RDS Snapshot Export | High | Elastic TOML |
| M365 SharePoint/OneDrive File Access via PowerShell | High | Elastic TOML |
| Access to a Sensitive LDAP Attribute | Medium | Elastic TOML |
| AWS Secrets Manager Rapid Secrets Retrieval | Medium | Elastic TOML |
| Azure Key Vault Excessive Secret or Key Retrieved | Medium | Elastic TOML |
| Entra ID Sharepoint or OneDrive Accessed by Unusual Client | Medium | Elastic TOML |
| First Time Seen NFS AUTH_SYS Root UID Access | Medium | Elastic TOML |
| GitHub Exfiltration via High Number of Repository Clones by User | Medium | Elastic TOML |
| Kubernetes Secret or ConfigMap Access via Azure Arc Proxy | Medium | Elastic TOML |
+ 8 more from elastic/detection-rules → showing the 10 highest-severity
SigmaHQ/sigma
12 rules| Detection | Severity | Format |
|---|---|---|
| Bitbucket Unauthorized Full Data Export Triggered | Critical | Sigma |
| Bitbucket Full Data Export Triggered | High | Sigma |
| OpenCanary - GIT Clone Request | High | Sigma |
| OpenCanary - MSSQL Login Attempt Via SQLAuth | High | Sigma |
| OpenCanary - MSSQL Login Attempt Via Windows Authentication | High | Sigma |
| OpenCanary - MySQL Login Attempt | High | Sigma |
| OpenCanary - REDIS Action Command Attempt | High | Sigma |
| Bitbucket User Details Export Attempt Detected | Medium | Sigma |
| Bitbucket User Permissions Export Attempt | Medium | Sigma |
| Github Delete Action Invoked | Medium | Sigma |
+ 2 more from SigmaHQ/sigma → showing the 10 highest-severity
panther-labs/panther-analysis
10 rules · 9 families| Detection | Severity | Format |
|---|---|---|
| Snowflake Data Exfiltration 2 variants | Critical | Panther Python |
| Snowflake Data Exfiltration 2 variants | Critical | Panther Python |
| External GSuite File Share | High | Panther Python |
| Okta SWA Bulk Access, New Source, and Credential Extraction - Behavioral | High | Panther Python |
| Zendesk Credit Card Redaction Off | High | Panther Python |
| AppOmni Alert Passthrough | Medium | Panther Python |
| Databricks TruffleHog Scan Detected | Medium | Panther Python |
| GSuite Document External Ownership Transfer | Low | Panther Python |
| GSuite External Drive Document | Low | Panther Python |
| GSuite Overly Visible Drive Document | Informational | Panther Python |
Azure/Azure-Sentinel
9 rules| Detection | Severity | Format |
|---|---|---|
| Users searching for VIP user activity | Low | KQL |
| Cross workspace query anomolies | Undefined | KQL |
| GitHub Repo Clone - Time Series Anomly | Undefined | KQL |
| GitHub Repo switched from private to public | Undefined | KQL |
| New client running queries | Undefined | KQL |
| New ServicePrincipal running queries | Undefined | KQL |
| New users calling sensitive Watchlist | Undefined | KQL |
| New users running queries | Undefined | KQL |
| Query looking for secrets | Undefined | KQL |
Wazuh Core Ruleset
4 rules| Detection | Severity | Format |
|---|---|---|
| Office 365: Suspicious download activity by user · rule 91724 | High | Wazuh XML |
| Office 365: Data loss protection (DLP) events in SharePoint and OneDrive for Business. | Low | Wazuh XML |
| Office 365: Events related to DLP classification in SharePoint. | Low | Wazuh XML |
| Office 365: SharePoint sharing events. | Low | Wazuh XML |
chronicle/detection-rules
3 rules| Detection | Severity | Format |
|---|---|---|
| github_access_granted_to_personal_access_token_followed_by_high_number_of_cloned_non_public_repositories | High | YARA-L |
| github_high_number_of_non_public_github_repositories_cloned | High | YARA-L |
| github_high_number_of_non_public_github_repositories_downloaded | High | YARA-L |
splunk/security_content
1 rule| Detection | Severity | Format |
|---|---|---|
| O365 SharePoint Suspicious Search Behavior | Undefined | SPL |