FORENSIA

ATT&CK · T1213

Data from Information Repositories

Tactics: collection

About

Adversaries may leverage information repositories to mine valuable information. Information repositories are tools that allow for storage of information, typically to facilitate collaboration or information sharing between users, and can store a wide variety of data that may aid adversaries in further objectives, such as Credential Access, Lateral Movement, or Defense Evasion, or direct access to the target information. Adversaries may also abuse external sharing features to share sensitive documents with recipients outside of the organization (i.e., Transfer Data to Cloud Account). The following is a brief list of example information that may hold potential value to an adversary and may also be found on an information repository: * Policies, procedures, and standards * Physical / logical network diagrams * System architecture diagrams * Technical system documentation * Testing / development credentials (i.e., Unsecured Credentials) * Work / project schedules * Source code snippets * Links to network shares and other internal resources * Contact or other sensitive information about business partners and customers, including personally identifiable information (PII) Information stored in a repository may vary based on the specific instance or environment. Specific common information repositories include the following: * Storage services such as IaaS databases, enterprise databases, and more specialized platforms such as customer relationship management (CRM) databases * Collaboration platforms such as SharePoint, Confluence, and code repositories * Messaging platforms such as Slack and Microsoft Teams In some cases, information repositories have been improperly secured, typically by unintentionally allowing for overly-broad access by all users or even public access to unauthenticated users. This is particularly common with cloud-native or cloud-hosted services, such as AWS Relational Database Service (RDS), Redis, or ElasticSearch.

Platforms: Linux, Windows, macOS, SaaS, IaaS, Office SuiteMITRE ATT&CK ↗

Used by actors

1 known groups

Software

2 malware/tools implement this

Raccoon StealerTroll Stealer

Corpus indicators tagged with this technique

125 indicators in the corpus carry T1213.

IndicatorTypeFamilySevSrc
4eebc38297a307d18784d6f9ebc8aa6e6f69860be970cc70d9e544deb1ff6ce0hash801
74bb6ad7e1310f30a3e24fd3cbbffa2c0c41c64e89e5d0dd1d6900e96b914183hash801
8a5dadc5faf424df1e8a0efad023df81hash801
03f26cbfa3ca15fcb43f512aa4041732beeec267f9d1dc74a11f7b0bb32e86bbsha256phishing801
f4d4b8cac004bb63834c6df436721babd9464c09787c80b268d839e0aada9f87hash801
ad1a0b3e22a10a2bd680b773b178a0d3824cfcbdf3551016f3d052a0b823079fsha256phishing801
523388567630e4fbdc359f75232bf2ad82671a680d4bfdce0237fc30dfec4c80hash801
7709d8c34d490509f3624104611eb75a862944dd9d7a642f44514ada16c85ee9hash801
9a59eb454f3ca3fe91214136ee5edd417cc47a80e6f169b52099d6561944baf9sha256supply_chain801
eb4e1394d537d8eba509dd5c57e7aaf4c1df57715c7161330012a11f6202af84sha256supply_chain801
90b7b2c6f3d05234dc55678243039d7e51f0d54190239e5234a0005533337dc8sha256phishing801
64107e3e0a333f685d1be6386426223a030c4126ac7c295aa7b1d54c508bbacesha256phishing801
2954639be599f23c2229a9743aba09a1d9d11bf2becc62bf353384437db37deesha256phishing801
643de2a1cf9148b896efecf560c9476fa56118ec477c4e15eb5c2da4b318061fsha256phishing801
442e0f4e822842922e7e4685840194e99fd68c7f0ec38c1925914b8f724d5865hash801
4a1a6ed11fd50b621659d7976899d050ba2e15d3hash801
6506d31707a39949f89534bf9705bcf889f1ecae3dbc6f4ff88d67a8be3d01b2hashsupply_chain802
6d332f814f15f19758d65026bbfd0a8c49671b319ec77b8fa1b27fc48afff7d9hashsupply_chain802
e5f6d9d405819e6b05b5d8268a2e973294859ad65237ede36ab612b536d0ac2bhash801
103c4e6181151c1bcfedc41506cd1815458c38375d08a8fcd9981dbe0b965ce0sha256supply_chain801
10ddbbae0070267b8d15888b09a3cdb19fa74d861315b71f21c9ace8b9f85c75sha256supply_chain801
4b188d179e50e8208a6efec85e273e88d8fc390c836f299ba12915e0840408fdsha256supply_chain801
1cac633d290a876fc1ead63c58de48575b67b1fcsha1phishing781
66049dd42a29dde7481d5ca2951efec27214ce15sha1phishing781
4da236de055bfaf08ee21fb6b88442b4md5phishing761
050b84a0d6105a98f443f0165368cc1cmd5phishing761
0a913561831bdf2c26dcf18b852b5cc1md5supply_chain761
c6851a038da578a80eeb201e0588c84cmd5supply_chain761
https://services.templatesearch-svc.org/search/url752
https://searchtoggler.com/ext/search?src=default&q=url752

Showing the top 30 by severity of 125.