FORENSIA

ATT&CK · T1119

Automated Collection

Tactics: collection

About

Once established within a system or network, an adversary may use automated techniques for collecting internal data. Methods for performing this technique could include use of a Command and Scripting Interpreter to search for and copy information fitting set criteria such as file type, location, or name at specific time intervals. In cloud-based environments, adversaries may also use cloud APIs, data pipelines, command line interfaces, or extract, transform, and load (ETL) services to automatically collect data. This functionality could also be built into remote access tools. This technique may incorporate use of other techniques such as File and Directory Discovery and Lateral Tool Transfer to identify and move files, as well as Cloud Service Dashboard and Cloud Storage Object Discovery to identify resources in cloud environments.

Platforms: IaaS, Linux, macOS, Office Suite, SaaS, WindowsMITRE ATT&CK ↗

Used by actors

21 known groups

Software

46 malware/tools implement this

RoverT9000BADNEWSUSBStealerRTMHelminthNETWIREProxysvcBankshotComnieZebrocyVERMINInvisiMoleMicropsiaEmpirePoshC2LightNeuronPoetRATAttorMESSAGETAPShimRatReporterMetamorfoRamsayWindTailTajMahalValakStrongPityCrutchGoldFinderAppleSeedROADToolsMythicOutSteelccf32FunnyDreamRotaJakiroPacuLoFiSePACEMAKERDarkGateNPPSPYRaccoon StealerStrelaStealerLumma StealerShai-HuludLAMEHUG

Corpus indicators tagged with this technique

331 indicators in the corpus carry T1119.

IndicatorTypeFamilySevSrc
449e4265979b5fdb2d3446c021af437e815debd66de7da2fe54f1ad93cbcc75ehashsupply_chain801
a648db354820ea4d02940cb1702b35974513b7aae83f6dffaacaac4ba31f9295hash803
66a3836b9a17771bce2161f6b73cbc2494a91e49d6aa30d2d53711e8d10de60dhash803
584a9448dda46bd590d7a2f86228100d2ae6e0d6d990c1a4459ed5ee28e07ae8hash803
8c9b6542f73c5c7fe455b52f5101314407da4f65ff48e7ebf6896605e607c8d0hash803
9d0a55c545c4147956db2c2667c4ed931a2875309147548b1dfdd216228f5f73hash803
0857148fb0bc4aa7adf967ede2307bdb4fc427065d5b6a6db132688a5a8e1eb8hash803
d6f479736ba55d3c4e895c4940d035cf772f3192fb8dc496f09a801aed16d970sha256phishing801
833008c03d40422192051584d829d730497108bef31751cceb0cc043dd96bbfbsha256phishing801
8111edf01ac6cb5c77e249d4e84fd92a85b5e89c2e2bef92fbe00b6f1cc2aa8esha256phishing801
4fcfa88fffacbce30bbe2136753c9ab5a4c092940d2406fd9d44d5118e745b9dhash803
3119cf37b8267db8a2dcd11d9a83d5237d7ef1e42388e7c9afa2831b91da8a2dhash803
40b41979b317406f8abc601677a3b93aaf6ef8ab8ac188b8f383735e388f13b5hash803
25b6fc4f9c54a28ba7bfc4dfeafb62c99b59ea6f0d17679219b876b321965095sha256phishing801
2758f4d71a2a2dfdefab81737c2d776b2a3dafe5844fdd2157e089a28447ca98sha256phishing801
067ad6221b2224d5cdb64e51c5516132d820cf4d7edf9ec170643943e79c04b7sha256phishing801
38353f95fff270f4e3a9d7add8c64666020dd668ce66e15969a736ec48cadc59sha256phishing801
4253dd1a4c0867b0be7732f75b2f630cebfb7fed94270e15fb3b12ae40546d01sha256phishing801
479ae5fd7274439ddfa27bc03298ebfdfc5ff17f6412acccf74d4dbd90d94218sha256phishing801
874bcb1c3d050a5b5b333a2198f504fcb27927c2abdd43b07440188a380c52d5sha256phishing801
9eaa577c8ba71646928c1c34c3145536b0498f65f26060a6ba00744bcef57644sha256phishing801
78a82d93b4f580835f5823b85a3d9ee1f03a15ee6f0e01b4eac86252a7002981hashsupply_chain801
f0038a5f46720da5982b6984ceef10cf99359432e102b12a0b0657498d36f670sha256phishing801
314f4b59535d1b783e1c20c2be00f9e30f8ed27b2e21fad06a73b47ea43279efhash803
3e7066e44132e64360a30974b6ea3671hash803
2d2a251a88632f010fd9671789746908eeccaa5bc5c0a5d25e4649efe4f5b15dhash803
0ffb16209def5500ff4380d9e8093437hash803
483a36fb9e4aef9704aa1e4edfb88c492dfe4140hash803
7b2c661cfb69e9c75df90d5102647bb014c28ad5hash803
96097e0612d9575cb133021017fb1a5c68a03b60f9f3d24ebdc0e628d9034144hashsupply_chain801

Showing the top 30 by severity of 331.