Automated Collection T1119
Tactic: Collection
Once established within a system or network, an adversary may use automated techniques for collecting internal data. Methods for performing this technique could include use of a Command and Scripting Interpreter to search for and copy information fitting set criteria such as file type, location, or name at specific time intervals.
Events covered
25 catalog events are tagged with this technique by at least one rule.
Authoring guide
These 41 rules share fields, values, and exclusions.
Fields filtered most (69 distinct)
These fields appear most often in rule filters.
Top indicator values (348 distinct)
These values appear most often in rule predicates.
Exclusions (63 distinct)
These values appear most often in top-level exclusions.
Rules under this technique
These vendors publish rules tagged with this technique.
Sigma 5 rules
- Automated Collection Command PowerShell
- Automated Collection Command Prompt
- Recon Information for Export with Command Prompt
- Recon Information for Export with PowerShell
- Shai-Hulud Malicious GitHub Workflow Creation
Elastic 8 rules
- AWS EC2 Export Task
- Environment Variable Secret Collection
- Exfiltration Data Staging in Temporary Directory via Osascript
- GCP Pub/Sub Subscription Creation
- Information Stealer Collection via Find
- Multi-Value Secret Searching via Find
- Multi-Value Secret Searching via Grep
- Potential Database Dumping Activity
Splunk 12 rules
- AWS Exfiltration via Anomalous GetObject API Activity
- AWS Exfiltration via Batch Service
- AWS Exfiltration via DataSync Task
- Executable Create Script Process (PowerShell)
- Executable Create Script Process (Sysmon)
- Executable Create Script Process (Windows Event Log)
- IcedID Discovery Commands (Sysmon)
- IcedID Discovery Commands (Windows Event Log)
- Linux Enumeration Techniques
- Windows Dir Piped to Findstr Activity
- Windows File Collection Via Copy Utilities
- Windows Process Accessing Windows Recall Directory
Kusto 16 rules
- ADWS Connection from Process Injection Target
- ADWS Connection from Unexpected Binary
- API - API Scraping
- Azure DevOps Audit Detection for known malicious tooling
- Hunt for ADWS requests from unknown devices
- Large number of AD objects accessed by user
- OracleDBAudit - Connection to database from external IP
- OracleDBAudit - Unusual user activity on multiple tables
- Snowflake - Query on sensitive or restricted table
- Snowflake - Unusual query
- Vectra Account's Behaviors
- Vectra AI Detect - Detections with High Severity
- Vectra AI Detect - Suspected Compromised Account
- Vectra AI Detect - Suspected Compromised Host
- Vectra AI Detect - Suspicious Behaviors by Category
- Vectra Host's Behaviors