Automated Collection T1119
Tactic: Collection
Once established within a system or network, an adversary may use automated techniques for collecting internal data. Methods for performing this technique could include use of a Command and Scripting Interpreter to search for and copy information fitting set criteria such as file type, location, or name at specific time intervals.
Events covered
24 catalog events are tagged with this technique by at least one rule.
Authoring guide
Patterns shared across the 35 rules above: which fields they filter on, what specific values they look for, and what they exclude. The catalog normalizes field names across vendors so Sigma's Image, Elastic's process.name, and Splunk's process_name collapse into one row. Each rule contributes at most once per row.
Fields filtered most (56 distinct)
The fields most rules look at when detecting this technique. The How column shows the operators authors use (eq, wildcard, regex_match, match) and how often each appears. Sample values are concrete examples to start from, not an exhaustive list.
Top indicator values (150 distinct)
Specific (field, operator, value) combinations the rules check for, ranked by how many rules under this technique use each one. The Corpus reach column counts how many rules across the entire catalog (any technique) check the same combination. High numbers point to widely-used indicators that are likely noisy on their own; combine them with another condition for useful signal. Blank means the combination is specific to rules under this technique. Click a value to expand the rules under this technique that use it.
Exclusions (16 distinct)
Field/operator/value combinations excluded by rules under this technique (top-level not() clauses), sorted by how many rules exclude each. These are the false-positive paths the community has learned to filter out. A new rule that ignores the high-count entries here will likely fire on the same noisy paths. Click a value to expand the rules under this technique that exclude it.
Rules under this technique
Every rule in the catalog tagged with this technique, grouped by vendor. Click a rule title for its full predicates, exclusions, and indicators.
Sigma 5 rules
- Automated Collection Command PowerShell
- Automated Collection Command Prompt
- Recon Information for Export with Command Prompt
- Recon Information for Export with PowerShell
- Shai-Hulud Malicious GitHub Workflow Creation
Elastic 3 rules
Splunk 11 rules
- AWS Exfiltration via Anomalous GetObject API Activity
- AWS Exfiltration via Batch Service
- AWS Exfiltration via DataSync Task
- Executable Create Script Process (PowerShell)
- Executable Create Script Process (Sysmon)
- Executable Create Script Process (Windows Event Log)
- IcedID Discovery Commands (EDR)
- IcedID Discovery Commands (Sysmon)
- IcedID Discovery Commands (Windows Event Log)
- Windows File Collection Via Copy Utilities
- Windows Process Accessing Windows Recall Directory
Kusto 16 rules
- ADWS Connection from Process Injection Target
- ADWS Connection from Unexpected Binary
- API - API Scraping
- Azure DevOps Audit Detection for known malicious tooling
- Hunt for ADWS requests from unknown devices
- Large number of AD objects accessed by user
- OracleDBAudit - Connection to database from external IP
- OracleDBAudit - Unusual user activity on multiple tables
- Snowflake - Query on sensitive or restricted table
- Snowflake - Unusual query
- Vectra Account's Behaviors
- Vectra AI Detect - Detections with High Severity
- Vectra AI Detect - Suspected Compromised Account
- Vectra AI Detect - Suspected Compromised Host
- Vectra AI Detect - Suspicious Behaviors by Category
- Vectra Host's Behaviors